https://bugzilla.suse.com/show_bug.cgi?id=1232643 Bug ID: 1232643 Summary: VUL-0: CVE-2024-50602: giada: libexpat: DoS via XML_ResumeParser Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/425799/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: edogawa@aon.at Reporter: Andreas.Stieger@gmx.de QA Contact: qa-bugs@suse.de CC: andrea.mattiazzo@suse.com, security-team@suse.de Blocks: 1232579 Target Milestone: --- Found By: --- Blocker: --- +++ This bug was initially created as a clone of Bug #1232611 +++ An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-50602 https://www.cve.org/CVERecord?id=CVE-2024-50602 https://github.com/libexpat/libexpat/pull/915 https://bugzilla.redhat.com/show_bug.cgi?id=2321987 The packages below are or contain embedded packages that are vulnerable to CVE-2024-50602. Tracking as affected: - openSUSE:Factory/giada contains embedded package: libexpat (R_2_1_0-26-gb3a467e) Please consider version bumping or patching the affected dependencies. The listed codestreams are affected. All other codestreams should not be affected, but feel free to double-check. This is a auto-generated message, please reach out to the reporter directly if you think this is incorrect. No bug-owner found for these packages, if the assignation is not correct feel free to re-assign. ./giada-1.0.0/src/deps/vst3sdk/vstgui4/vstgui/uidescription/expat ./giada-1.0.0/src/deps/vst3sdk/vstgui4/vstgui/uidescription/expat/expat_external.h ./giada-1.0.0/src/deps/vst3sdk/vstgui4/vstgui/uidescription/expat/expat.h -- You are receiving this mail because: You are on the CC list for the bug.