https://seclists.org/oss-sec/2025/q2/33: xmlrpc-c bundles a (very old and) vulnerable copy of libexpat
Published Apr 9, 2025
·Updated
Affected Software
3 affected components
Red Hat xmlrpc-c
OpenWrt xmlrpc-c
Gentoo xmlrpc-c
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is classified as high due to the vulnerabilities in the bundled version of libexpat.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, you should upgrade to the latest version of xmlrpc-c that includes an updated version of libexpat.
3
Which software is affected by CVE-2025-XXXX?
CVE-2025-XXXX affects xmlrpc-c used in Red Hat, OpenWrt, and Gentoo distributions.
4
Is there a workaround for CVE-2025-XXXX?
A potential workaround for CVE-2025-XXXX includes using a different XML library instead of the vulnerable libexpat.
5
What is the impact of CVE-2025-XXXX on my system?
The impact of CVE-2025-XXXX on your system can include potential code execution or denial of service attacks if the vulnerability is exploited.