Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-04541
HistoryJan 14, 2022 - 12:00 a.m.

Expat defineAttribute function buffer overflow vulnerability

2022-01-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
expat
xml parser
buffer overflow
defineattribute function
version 2.4.3
boundary error
untrusted input
remote attacker
arbitrary code
system security
vulnerability
exploit

EPSS

0.015

Percentile

87.1%

Expat is a fast streaming XML parser written in C. A buffer overflow vulnerability exists in versions of Expat prior to 2.4.3, which stems from a boundary error in defineAttribute in xmlparse.c when handling untrusted input. A remote attacker could exploit this vulnerability to execute arbitrary code on the system.