Bug ID 1232591
Summary VUL-0: CVE-2024-50602: tdom: libexpat: DoS via XML_ResumeParser
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.5
Hardware Other
URL https://smash.suse.de/issue/425799/
OS Other
Status NEW
Whiteboard CVSSv3.1:SUSE:CVE-2024-50602:5.5:(AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Severity Normal
Priority P5 - None
Component Security
Assignee max@suse.com
Reporter andrea.mattiazzo@suse.com
QA Contact security-team@suse.de
Blocks 1232579
Target Milestone ---
Found By ---
Blocker ---

An issue was discovered in libexpat before 2.6.4. There is a crash within the
XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted
parser.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-50602
https://www.cve.org/CVERecord?id=CVE-2024-50602
https://github.com/libexpat/libexpat/pull/915
https://bugzilla.redhat.com/show_bug.cgi?id=2321987


You are receiving this mail because: