CVE-2024-45490
EUVD-2024-4150930.08.2024, 03:15
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libexpat_project | libexpat | 𝑥 < 2.6.3 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| libexpat_project | libexpat | 𝑥 < 2.6.3 | ADP |
| Siemens | RUGGEDCOM RST2428P | 𝑥 < V3.1 | ADP |
| Siemens | SCALANCE XC-300\/XR-300\/XC-400\/XR-500WG\/XR-500 family | 𝑥 < * | ADP |
| Siemens | SCALANCE XCM-\/XRM-\/XCH-\/XRH-300 family | 𝑥 < V3.1 | ADP |
| Siemens | SIMATIC S7-1500 CPU 1518-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | SIMATIC S7-1500 CPU 1518-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | SIMATIC S7-1500 CPU 1518F-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | SIMATIC S7-1500 CPU 1518F-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | SIPLUS S7-1500 CPU 1518-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| expat |
| ||||||||||||||||||
| apache2 |
| ||||||||||||||||||
| apr-util |
| ||||||||||||||||||
| cmake |
| ||||||||||||||||||
| ghostscript |
| ||||||||||||||||||
| texlive-bin |
| ||||||||||||||||||
| xmlrpc-c |
| ||||||||||||||||||
| vnc4 |
| ||||||||||||||||||
| wbxml2 |
| ||||||||||||||||||
| swish-e |
| ||||||||||||||||||
| insighttoolkit4 |
| ||||||||||||||||||
| cadaver |
| ||||||||||||||||||
| gdcm |
| ||||||||||||||||||
| ayttm |
| ||||||||||||||||||
| cableswig |
| ||||||||||||||||||
| coin3 |
| ||||||||||||||||||
| matanza |
| ||||||||||||||||||
| tdom |
| ||||||||||||||||||
| vtk |
| ||||||||||||||||||
| smart |
| ||||||||||||||||||
| firefox |
| ||||||||||||||||||
| thunderbird |
| ||||||||||||||||||
| libxmltok |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| expat |
| ||||||||||||||||||||||||||
| libexpat-devel |
| ||||||||||||||||||||||||||
| libexpat1 |
| ||||||||||||||||||||||||||
| libexpat1-32bit |
| ||||||||||||||||||||||||||
| libmozjs-115-0 |
| ||||||||||||||||||||||||||
| libmozjs-60 |
| ||||||||||||||||||||||||||
| libmozjs-78-0 |
| ||||||||||||||||||||||||||
| mozjs115-devel |
| ||||||||||||||||||||||||||
| mozjs60-devel |
| ||||||||||||||||||||||||||
| mozjs78-devel |
| ||||||||||||||||||||||||||
| x3270 |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
- CWE-611 - Improper Restriction of XML External Entity ReferenceThe software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
- CWE-190 - Integer Overflow or WraparoundThe software performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.
References