Back

HIGH

expat: heap-based buffer over-read via crafted XML input

Published Sep 4, 2019

Description

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (63)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 4, 2019
Updated May 30, 2025
Reserved Sep 4, 2019
CISA Vulnrichment
Updated May 30, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 4, 2019