PT-2025-46012 · Julia · Expat Jll
Published
2025-10-14
·
Updated
2025-10-14
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML GetCurrentLineNumber (or XML GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Expat Jll