Lucene search

K
redhatcveRedhat.comRH:CVE-2019-15903
HistoryDec 28, 2019 - 3:54 a.m.

CVE-2019-15903

2019-12-2803:54:22
redhat.com
access.redhat.com
19

0.005 Low

EPSS

Percentile

76.5%

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.