4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
7.9 High
AI Score
Confidence
High
0.002 Low
EPSS
Percentile
56.6%
readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.
CPE | Name | Operator | Version |
---|---|---|---|
apple:mac_os_x | apple mac os x | eq | 10.11.0 |
apple:mac_os_x | apple mac os x | eq | 10.11.1 |
expat.cvs.sourceforge.net/viewvc/expat/expat/xmlwf/readfilemap.c?r1=1.14&r2=1.15
lists.apple.com/archives/security-announce/2015/Dec/msg00005.html
sourceforge.net/projects/expat/files/expat/2.1.0/
sourceforge.net/tracker/?func=detail&aid=2895533&group_id=10127&atid=110127
trac.wxwidgets.org/ticket/11194
trac.wxwidgets.org/ticket/11432
www.securityfocus.com/bid/52379
www.securitytracker.com/id/1034344
support.apple.com/HT205637
More