expat: heap-based buffer over-read via crafted XML input
Published Sep 4, 2019
7.5
HIGHCVSS 3.1
EPSS 6.64%
Description
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Affected products
No data.
No data.
JBoss Core Services on RHEL 6
jbcs-httpd24-curl-0:7.64.1-36.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:7.64.1-36.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-pkcs11-0:0.4.10-7.jbcs.el7
Fixed · RHSA-2020:2644
Red Hat Enterprise Linux 6
thunderbird-0:68.2.0-2.el6_10
Fixed · RHSA-2019:3756
Red Hat Enterprise Linux 7
expat-0:2.1.0-12.el7
Fixed · RHSA-2020:3952
Red Hat Enterprise Linux 7
firefox-0:68.2.0-1.el7_7
Fixed · RHSA-2019:3193
Red Hat Enterprise Linux 7
thunderbird-0:68.2.0-1.el7_7
Fixed · RHSA-2019:3210
Red Hat Enterprise Linux 8
expat-0:2.2.5-4.el8
Fixed · RHSA-2020:4484
Red Hat Enterprise Linux 8
firefox-0:68.2.0-2.el8_0
Fixed · RHSA-2019:3196
Red Hat Enterprise Linux 8
thunderbird-0:68.2.0-1.el8_0
Fixed · RHSA-2019:3237
Red Hat Enterprise Linux 8.2 Advanced Update Support
expat-0:2.2.10-1.el8_2
Fixed · RHSA-2025:22871
Red Hat JBoss Core Services
expat
Fixed · RHSA-2020:2646
Red Hat OpenShift Do
openshiftdo/odo-init-image-rhel7:1.1.3-2
Fixed · RHSA-2021:0949
Red Hat Enterprise Linux 5
expat
Out of support scope
Red Hat Enterprise Linux 5
firefox
Out of support scope
Red Hat Enterprise Linux 5
thunderbird
Out of support scope
Red Hat Enterprise Linux 5
xmlrpc-c
Out of support scope
Red Hat Enterprise Linux 5
xulrunner
Not affected
Red Hat Enterprise Linux 6
compat-expat1
Out of support scope
Red Hat Enterprise Linux 6
expat
Out of support scope
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 6
xulrunner
Not affected
Red Hat Enterprise Linux 7
python
Not affected
Red Hat Enterprise Linux 7
xulrunner
Not affected
Red Hat Enterprise Linux 8
mingw-expat
Affected
Red Hat Enterprise Linux 8
python2
Not affected
Red Hat Enterprise Linux 8
python3
Not affected
Red Hat JBoss Enterprise Application Platform 6
httpd
Out of support scope
Red Hat JBoss Enterprise Web Server 2
httpd
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services on RHEL 6 | jbcs-httpd24-curl-0:7.64.1-36.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:7.64.1-36.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-pkcs11-0:0.4.10-7.jbcs.el7 | Fixed | RHSA-2020:2644 |
| Red Hat Enterprise Linux 6 | thunderbird-0:68.2.0-2.el6_10 | Fixed | RHSA-2019:3756 |
| Red Hat Enterprise Linux 7 | expat-0:2.1.0-12.el7 | Fixed | RHSA-2020:3952 |
| Red Hat Enterprise Linux 7 | firefox-0:68.2.0-1.el7_7 | Fixed | RHSA-2019:3193 |
| Red Hat Enterprise Linux 7 | thunderbird-0:68.2.0-1.el7_7 | Fixed | RHSA-2019:3210 |
| Red Hat Enterprise Linux 8 | expat-0:2.2.5-4.el8 | Fixed | RHSA-2020:4484 |
| Red Hat Enterprise Linux 8 | firefox-0:68.2.0-2.el8_0 | Fixed | RHSA-2019:3196 |
| Red Hat Enterprise Linux 8 | thunderbird-0:68.2.0-1.el8_0 | Fixed | RHSA-2019:3237 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | expat-0:2.2.10-1.el8_2 | Fixed | RHSA-2025:22871 |
| Red Hat JBoss Core Services | expat | Fixed | RHSA-2020:2646 |
| Red Hat OpenShift Do | openshiftdo/odo-init-image-rhel7:1.1.3-2 | Fixed | RHSA-2021:0949 |
| Red Hat Enterprise Linux 5 | expat | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | xmlrpc-c | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | xulrunner | Not affected | n/a |
| Red Hat Enterprise Linux 6 | compat-expat1 | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | expat | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | xulrunner | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | xulrunner | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-expat | Affected | n/a |
| Red Hat Enterprise Linux 8 | python2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3 | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | httpd | Out of support scope | n/a |
| Red Hat JBoss Enterprise Web Server 2 | httpd | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (63)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00080.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00081.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00003.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00013.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00016.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00017.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00018.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00019.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/154503/Slackware-Security-Advisory-expat-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154947/Slackware-Security-Advisory-mozilla-firefox-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Dec/23 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/26 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/27 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/30 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3210 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3237 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3756 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-15903 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1752592 Issue Tracking
- https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43 x_refsource_MISCPatchThird Party Advisory
- https://github.com/libexpat/libexpat/issues/317 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/libexpat/libexpat/issues/342 x_refsource_CONFIRMThird Party Advisory
- https://github.com/libexpat/libexpat/pull/318 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00006.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00017.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BDUTI5TVQWIGGQXPEVI4T2ENHFSBMIBP/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S26LGXXQ7YF2BP3RGOWELBFKM6BHF6UG/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-15903
- https://seclists.org/bugtraq/2019/Dec/17 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Dec/21 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Dec/23 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Nov/1 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Nov/24 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Oct/29 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Sep/30 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Sep/37 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201911-08 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190926-0004/ x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210785 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210788 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210789 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210790 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210793 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210794 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210795 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4132-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4132-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4165-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4202-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4335-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-15903
- https://www.debian.org/security/2019/dsa-4530 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2019/dsa-4549 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2019/dsa-4571 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCThird Party Advisory
- https://www.tenable.com/security/tns-2021-11 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.