Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21433
HistorySep 05, 2019 - 6:48 a.m.

Denial Of Service (Dos)

2019-09-0506:48:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

0.005 Low

EPSS

Percentile

76.5%

libexpat.so is vulnerable to denial of service. A heap-based buffer overflow occurs when an attacker sends a malicious XML which switches the DTD parsing to document parsing immaturely, leading to repeated calls of XML_GetCurrentLineNumber or XML_GetCurrentColumnNumber function that results in an application crash.

References