Related Vulnerabilities: CVE-2022-25313  

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

Description

The MITRE CVE dictionary describes this issue as:

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

Additional Information

  • Bugzilla 2056350: CVE-2022-25313 expat: Stack exhaustion in build_model() via uncontrolled recursion
  • CWE-400: Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2022-25313