storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libexpat | Libexpat_project | * | 2.4.3 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | expat-0:2.1.0-14.el7_9 | * |
Red Hat Enterprise Linux 8 | RedHat | expat-0:2.2.5-4.el8_5.3 | * |
Red Hat Enterprise Linux 8 | RedHat | xmlrpc-c-0:1.51.0-8.el8 | * |
Red Hat JBoss Core Services 1 | RedHat | expat | * |
Apache2 | Ubuntu | trusty | * |
Apr-util | Ubuntu | trusty | * |
Ayttm | Ubuntu | trusty | * |
Ayttm | Ubuntu | xenial | * |
Cableswig | Ubuntu | trusty | * |
Cableswig | Ubuntu | xenial | * |
Cadaver | Ubuntu | bionic | * |
Cadaver | Ubuntu | hirsute | * |
Cadaver | Ubuntu | impish | * |
Cadaver | Ubuntu | kinetic | * |
Cadaver | Ubuntu | lunar | * |
Cadaver | Ubuntu | mantic | * |
Cadaver | Ubuntu | trusty | * |
Cadaver | Ubuntu | xenial | * |
Cmake | Ubuntu | trusty | * |
Coin3 | Ubuntu | bionic | * |
Coin3 | Ubuntu | trusty | * |
Coin3 | Ubuntu | trusty/esm | * |
Coin3 | Ubuntu | xenial | * |
Expat | Ubuntu | bionic | * |
Expat | Ubuntu | devel | * |
Expat | Ubuntu | esm-infra/xenial | * |
Expat | Ubuntu | focal | * |
Expat | Ubuntu | hirsute | * |
Expat | Ubuntu | impish | * |
Expat | Ubuntu | jammy | * |
Expat | Ubuntu | kinetic | * |
Expat | Ubuntu | lunar | * |
Expat | Ubuntu | mantic | * |
Expat | Ubuntu | noble | * |
Expat | Ubuntu | oracular | * |
Expat | Ubuntu | trusty | * |
Expat | Ubuntu | trusty/esm | * |
Expat | Ubuntu | xenial | * |
Firefox | Ubuntu | bionic | * |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | focal | * |
Firefox | Ubuntu | impish | * |
Firefox | Ubuntu | jammy | * |
Firefox | Ubuntu | kinetic | * |
Firefox | Ubuntu | lunar | * |
Firefox | Ubuntu | mantic | * |
Firefox | Ubuntu | noble | * |
Firefox | Ubuntu | oracular | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | upstream | * |
Firefox | Ubuntu | xenial | * |
Gdcm | Ubuntu | trusty | * |
Ghostscript | Ubuntu | trusty | * |
Insighttoolkit | Ubuntu | trusty | * |
Insighttoolkit | Ubuntu | xenial | * |
Insighttoolkit4 | Ubuntu | hirsute | * |
Insighttoolkit4 | Ubuntu | impish | * |
Insighttoolkit4 | Ubuntu | trusty | * |
Insighttoolkit4 | Ubuntu | xenial | * |
Libxmltok | Ubuntu | bionic | * |
Libxmltok | Ubuntu | devel | * |
Libxmltok | Ubuntu | esm-apps/bionic | * |
Libxmltok | Ubuntu | esm-apps/focal | * |
Libxmltok | Ubuntu | esm-apps/jammy | * |
Libxmltok | Ubuntu | esm-apps/noble | * |
Libxmltok | Ubuntu | esm-apps/xenial | * |
Libxmltok | Ubuntu | focal | * |
Libxmltok | Ubuntu | hirsute | * |
Libxmltok | Ubuntu | impish | * |
Libxmltok | Ubuntu | jammy | * |
Libxmltok | Ubuntu | kinetic | * |
Libxmltok | Ubuntu | lunar | * |
Libxmltok | Ubuntu | mantic | * |
Libxmltok | Ubuntu | noble | * |
Libxmltok | Ubuntu | oracular | * |
Libxmltok | Ubuntu | trusty | * |
Libxmltok | Ubuntu | xenial | * |
Matanza | Ubuntu | bionic | * |
Matanza | Ubuntu | hirsute | * |
Matanza | Ubuntu | impish | * |
Matanza | Ubuntu | kinetic | * |
Matanza | Ubuntu | lunar | * |
Matanza | Ubuntu | mantic | * |
Matanza | Ubuntu | trusty | * |
Matanza | Ubuntu | xenial | * |
Smart | Ubuntu | trusty | * |
Swish-e | Ubuntu | bionic | * |
Swish-e | Ubuntu | hirsute | * |
Swish-e | Ubuntu | impish | * |
Swish-e | Ubuntu | kinetic | * |
Swish-e | Ubuntu | lunar | * |
Swish-e | Ubuntu | mantic | * |
Swish-e | Ubuntu | trusty | * |
Swish-e | Ubuntu | xenial | * |
Tdom | Ubuntu | bionic | * |
Tdom | Ubuntu | hirsute | * |
Tdom | Ubuntu | impish | * |
Tdom | Ubuntu | kinetic | * |
Tdom | Ubuntu | lunar | * |
Tdom | Ubuntu | mantic | * |
Tdom | Ubuntu | trusty | * |
Tdom | Ubuntu | xenial | * |
Texlive-bin | Ubuntu | trusty | * |
Thunderbird | Ubuntu | bionic | * |
Thunderbird | Ubuntu | focal | * |
Thunderbird | Ubuntu | hirsute | * |
Thunderbird | Ubuntu | impish | * |
Thunderbird | Ubuntu | jammy | * |
Thunderbird | Ubuntu | kinetic | * |
Thunderbird | Ubuntu | trusty | * |
Thunderbird | Ubuntu | xenial | * |
Vnc4 | Ubuntu | bionic | * |
Vnc4 | Ubuntu | trusty | * |
Vnc4 | Ubuntu | trusty/esm | * |
Vnc4 | Ubuntu | xenial | * |
Vtk | Ubuntu | trusty | * |
Vtk | Ubuntu | trusty/esm | * |
Vtk | Ubuntu | xenial | * |
Wbxml2 | Ubuntu | bionic | * |
Wbxml2 | Ubuntu | hirsute | * |
Wbxml2 | Ubuntu | impish | * |
Wbxml2 | Ubuntu | kinetic | * |
Wbxml2 | Ubuntu | lunar | * |
Wbxml2 | Ubuntu | mantic | * |
Wbxml2 | Ubuntu | trusty | * |
Wbxml2 | Ubuntu | xenial | * |
Xmlrpc-c | Ubuntu | bionic | * |
Xmlrpc-c | Ubuntu | hirsute | * |
Xmlrpc-c | Ubuntu | impish | * |
Xmlrpc-c | Ubuntu | kinetic | * |
Xmlrpc-c | Ubuntu | lunar | * |
Xmlrpc-c | Ubuntu | mantic | * |
Xmlrpc-c | Ubuntu | trusty | * |
Xmlrpc-c | Ubuntu | trusty/esm | * |
Xmlrpc-c | Ubuntu | xenial | * |