NA

CVE-2024-28757

Published: 10/03/2024 Updated: 23/03/2024

Vulnerability Summary

libexpat up to and including 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1065868 expat: CVE-2024-28757 Package: src:expat; Maintainer for src:expat is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 10 Mar 2024 15:03:07 UTC Severity: important Tags: security, upstream Found in version expat/261-1 Fixe ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Expat 262 released, includes security fixes <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Alan Coopersmith &l ...