CVE-2023-52425

libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

History

09 Apr 2024, 06:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00006.html -

26 Feb 2024, 16:27

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV/ -

09 Feb 2024, 02:03

Type Values Removed Values Added
CPE cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*
First Time Libexpat Project libexpat
Libexpat Project
Summary
  • (es) libexpat hasta 2.5.0 permite una denegación de servicio (consumo de recursos) porque se requieren muchos análisis completos en el caso de un token grande para el cual se necesitan múltiples rellenos de búfer.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-400
References () https://github.com/libexpat/libexpat/pull/789 - () https://github.com/libexpat/libexpat/pull/789 - Exploit, Vendor Advisory

04 Feb 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-04 20:15

Updated : 2024-04-09 06:15


NVD link : CVE-2023-52425

Mitre link : CVE-2023-52425

CVE.ORG link : CVE-2023-52425


JSON object : View

Products Affected

libexpat_project

  • libexpat
CWE
CWE-400

Uncontrolled Resource Consumption