PT-2024-6339 · Libexpat+11 · Libexpat+11

Taiyou

·

Published

2024-08-26

·

Updated

2026-04-01

·

CVE-2024-45492

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libexpat versions prior to 2.6.3
Description An issue was discovered in libexpat, where the nextScaffoldPart function in xmlparse.c can have an integer overflow for m groupSize on 32-bit platforms. This can allow a remote attacker to cause a denial of service or execute arbitrary code. The issue is related to the failure to properly handle integer overflows, which can lead to security vulnerabilities.
Recommendations For libexpat versions prior to 2.6.3, update to version 2.6.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the nextScaffoldPart function in xmlparse.c to minimize the risk of exploitation. Avoid using libexpat on 32-bit platforms until the issue is resolved.

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:6754
ALSA-2024:6989
ALT-PU-2024-17539
AZL-48394
AZL-48466
BDU:2024-07376
CESA-2024_6989
CLEANSTART-2026-EM10970
CLEANSTART-2026-MH09144
CLEANSTART-2026-YT18139
CVE-2024-45492
DLA-3893-1
DSA-5770-1
INFSA-2024_6754
INFSA-2024_6989
MGASA-2024-0294
MGASA-2024-0338
OESA-2024-2121
OPENSUSE-SU-2024:14322-1
OPENSUSE-SU-2024:14328-1
OPENSUSE-SU-2024:14379-1
OPENSUSE-SU-2024:14380-1
OPENSUSE-SU-2024:14381-1
OPENSUSE-SU-2024:14548-1
OPENSUSE-SU-2024_3216-1
OPENSUSE-SU-2024_3538-1
OPENSUSE-SU-2024_3554-1
RHSA-2024:6754
RHSA-2024:6989
RHSA-2024_6754
RHSA-2024_6989
RLSA-2024:6754
RLSA-2024:6989
SUSE-SU-2024:3182-1
SUSE-SU-2024:3216-1
SUSE-SU-2024:3515-1
SUSE-SU-2024:3538-1
SUSE-SU-2024:3554-1
SUSE-SU-2025:20045-1
SUSE-SU-2025:20207-1
SUSE-SU-2025:20311-1
SUSE-SU-2025:4512-1
SUSE-SU-2026:0044-1
USN-7000-1
USN-7000-2

Affected Products

Alt Linux
Almalinux
Centos
Debian
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libexpat