In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libexpat | Libexpat_project | * | 2.8.1 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | expat-0:2.7.3-1.el10_2.1 | * |
| Red Hat Enterprise Linux 8 | RedHat | expat-0:2.5.0-2.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | expat-0:2.5.0-6.el9_8.1 | * |
| Red Hat Enterprise Linux 9 | RedHat | expat-0:2.5.0-6.el9_8.1 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1781525684 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1781525671 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1781525693 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1781525739 | * |
| Ayttm | Ubuntu | esm-apps/xenial | * |
| Cableswig | Ubuntu | esm-apps/xenial | * |
| Cadaver | Ubuntu | esm-apps/xenial | * |
| Coin3 | Ubuntu | esm-apps/xenial | * |
| Expat | Ubuntu | esm-infra/xenial | * |
| Gdcm | Ubuntu | esm-apps/xenial | * |
| Insighttoolkit4 | Ubuntu | esm-apps/xenial | * |
| Libxmltok | Ubuntu | esm-apps/xenial | * |
| Matanza | Ubuntu | devel | * |
| Matanza | Ubuntu | esm-apps/focal | * |
| Matanza | Ubuntu | esm-apps/jammy | * |
| Matanza | Ubuntu | esm-apps/noble | * |
| Matanza | Ubuntu | esm-apps/resolute | * |
| Matanza | Ubuntu | esm-apps/xenial | * |
| Matanza | Ubuntu | jammy | * |
| Matanza | Ubuntu | noble | * |
| Matanza | Ubuntu | questing | * |
| Matanza | Ubuntu | resolute | * |
| Smart | Ubuntu | esm-apps/xenial | * |
| Swish-e | Ubuntu | esm-apps/xenial | * |
| Tdom | Ubuntu | esm-apps/xenial | * |
| Vnc4 | Ubuntu | esm-apps/xenial | * |
| Vtk | Ubuntu | esm-apps/xenial | * |
| Wbxml2 | Ubuntu | esm-apps/xenial | * |
| Xmlrpc-c | Ubuntu | esm-apps/xenial | * |