Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37678
HistoryOct 25, 2022 - 5:03 a.m.

Use After Free

2022-10-2505:03:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
libexpat.so
use-after-free
xml_parserfree
entity value validations
xmlparse.c
memory consumption
application crash

0.004 Low

EPSS

Percentile

74.1%

libexpat.so is vulnerable to use-after-free. The vulnerability exists due to a lack of entity value validations in the XML_ParserFree parameter of the parserCreate function in xmlparse.c. An attacker could exploit it to lead to memory consumption resulting in an application crash.

References