CVE-2021-46143

Description

In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
4.085

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.2Windows
Multiple vulnerabilities are fixed in IBM HTTP 9.0.5.11Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
expat security update(DSA-5073-1) expat_2.2.6-2+deb10u2_amd64.debLinux
expat security update(DSA-5073-1) expat_2.2.6-2+deb10u2_i386.debLinux
expat security update(DSA-5073-1) Debian_expat_2.2.6-2+deb10u2_amd64.debLinux
expat security update(DSA-5073-1) expat_2.2.10-2+deb11u1_amd64.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.2.5-3ubuntu0.7_i386.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.2.5-3ubuntu0.7_amd64.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.2.9-1ubuntu0.4_i386.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.2.9-1ubuntu0.4_amd64.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.4.1-2ubuntu0.3_i386.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.4.1-2ubuntu0.3_amd64.debLinux
(RHSA-2022:0951) expat security update expat-debugsource-2.2.5-4.el8_5.3.i686.rpmLinux
(RHSA-2022:0951) expat security update expat-debugsource-2.2.5-4.el8_5.3.x86_64.rpmLinux
(RHSA-2022:1069) expat security update expat-2.1.0-14.el7_9.i686.rpmLinux
(RHSA-2022:1069) expat security update expat-2.1.0-14.el7_9.x86_64.rpmLinux
(RHSA-2022:1069) expat security update expat-devel-2.1.0-14.el7_9.i686.rpmLinux
(RHSA-2022:1069) expat security update expat-devel-2.1.0-14.el7_9.x86_64.rpmLinux
(RHSA-2022:1069) expat security update expat-static-2.1.0-14.el7_9.i686.rpmLinux
(RHSA-2022:1069) expat security update expat-static-2.1.0-14.el7_9.x86_64.rpmLinux
Expat update (ELSA-2022-0951) expat-2.2.5-4.el8_5.3.i686.rpmLinux
Expat update (ELSA-2022-0951) expat-2.2.5-4.el8_5.3.x86_64.rpmLinux
Expat-devel update (ELSA-2022-0951) expat-devel-2.2.5-4.el8_5.3.i686.rpmLinux
Expat-devel update (ELSA-2022-0951) expat-devel-2.2.5-4.el8_5.3.x86_64.rpmLinux
Expat update (ELSA-2022-9227) expat-2.1.0-12.0.1.el7.i686.rpmLinux
Expat update (ELSA-2022-9227) expat-2.1.0-12.0.1.el7.x86_64.rpmLinux
Expat-devel update (ELSA-2022-9227) expat-devel-2.1.0-12.0.1.el7.i686.rpmLinux
Expat-devel update (ELSA-2022-9227) expat-devel-2.1.0-12.0.1.el7.x86_64.rpmLinux
Expat-static update (ELSA-2022-9227) expat-static-2.1.0-12.0.1.el7.i686.rpmLinux
Expat-static update (ELSA-2022-9227) expat-static-2.1.0-12.0.1.el7.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) expat-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) expat-debuginfo-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) expat-debuginfo-32bit-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) expat-debugsource-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) libexpat1-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) libexpat1-32bit-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) libexpat1-debuginfo-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) libexpat1-debuginfo-32bit-2.1.0-21.12.1.x86_64.rpmLinux
Expat update (ELSA-2022-1069) expat-2.1.0-14.0.1.el7_9.i686.rpmLinux
Expat update (ELSA-2022-1069) expat-2.1.0-14.0.1.el7_9.x86_64.rpmLinux
Expat-devel update (ELSA-2022-1069) expat-devel-2.1.0-14.0.1.el7_9.i686.rpmLinux
Expat-devel update (ELSA-2022-1069) expat-devel-2.1.0-14.0.1.el7_9.x86_64.rpmLinux
Expat-static update (ELSA-2022-1069) expat-static-2.1.0-14.0.1.el7_9.i686.rpmLinux
Expat-static update (ELSA-2022-1069) expat-static-2.1.0-14.0.1.el7_9.x86_64.rpmLinux
xmlrpc-c security update (RLSA-2022:7692) xmlrpc-c-1.51.0-8.el8.i686.rpmLinux
xmlrpc-c security update (RLSA-2022:7692) xmlrpc-c-1.51.0-8.el8.x86_64.rpmLinux
xmlrpc-c security update (RLSA-2022:7692) xmlrpc-c-client-1.51.0-8.el8.i686.rpmLinux
xmlrpc-c security update (RLSA-2022:7692) xmlrpc-c-client-1.51.0-8.el8.x86_64.rpmLinux
Xmlrpc-c update (ELSA-2022-7692) xmlrpc-c-1.51.0-8.el8.i686.rpmLinux
Xmlrpc-c update (ELSA-2022-7692) xmlrpc-c-1.51.0-8.el8.x86_64.rpmLinux
Xmlrpc-c-client update (ELSA-2022-7692) xmlrpc-c-client-1.51.0-8.el8.i686.rpmLinux
Xmlrpc-c-client update (ELSA-2022-7692) xmlrpc-c-client-1.51.0-8.el8.x86_64.rpmLinux
XML Parser Toolkit, runtime libraries (USN-7199-1) libxmltok1t64_1.2-4.1ubuntu3.1_amd64.debLinux
library for rendering vector based animations and art (USN-7198-1) libxmltok1t64_1.2-4.1ubuntu3.1_amd64.debLinux
expat Security Update (ALAS2023-2023-058) expat-2.5.0-1.amzn2023.0.2.x86_64.rpmLinux
expat Security Update (ALAS2023-2023-058) expat-devel-2.5.0-1.amzn2023.0.2.x86_64.rpmLinux
expat Security Update (ALAS2023-2023-058) expat-static-2.5.0-1.amzn2023.0.2.x86_64.rpmLinux
Integer Overflow or Wraparound Vulnerability (CVE-2021-46143)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234