icon

We found results for “

CVE-2024-45490

Good to know:

icon

Date: August 29, 2024

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

Language: C

Severity Score

Severity Score

Weakness Type (CWE)

Improper Restriction of XML External Entity Reference

CWE-611

Integer Overflow or Wraparound

CWE-190

Top Fix

icon

Upgrade Version

Upgrade to version cmake - no_fix;cmake - 3.17.3;cmake - 3.23.1;cmake - 3.22.0;cmake - 3.20.1;python3 - 3.8.2;hxcadaptor-sys - 0.1.2;xmp_toolkit - 0.3.6;xmp_toolkit - no_fix;hxcfe-sys - no_fix;expat - no_fix;expat-sys - no_fix;cmake-native - 3.22.0;cmake-native - 3.18.2;cmake-native - 3.23.2;openfx-sys - no_fix;org.webjars.npm:node-expat:2.3.18

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us