Bug ID 1232643
Summary VUL-0: CVE-2024-50602: giada: libexpat: DoS via XML_ResumeParser
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/425799/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee edogawa@aon.at
Reporter Andreas.Stieger@gmx.de
QA Contact qa-bugs@suse.de
CC andrea.mattiazzo@suse.com, security-team@suse.de
Blocks 1232579
Target Milestone ---
Found By ---
Blocker ---

+++ This bug was initially created as a clone of Bug #1232611 +++

An issue was discovered in libexpat before 2.6.4. There is a crash within the
XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted
parser.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-50602
https://www.cve.org/CVERecord?id=CVE-2024-50602
https://github.com/libexpat/libexpat/pull/915
https://bugzilla.redhat.com/show_bug.cgi?id=2321987

The packages below are or contain embedded packages that are vulnerable to
CVE-2024-50602.

Tracking as affected:
- openSUSE:Factory/giada contains embedded package: libexpat
(R_2_1_0-26-gb3a467e)

Please consider version bumping or patching the affected dependencies.
The listed codestreams are affected. All other codestreams should not be
affected, but feel free to double-check.
This is a auto-generated message, please reach out to the reporter directly if
you think this is incorrect.
No bug-owner found for these packages, if the assignation is not correct feel
free to re-assign.

./giada-1.0.0/src/deps/vst3sdk/vstgui4/vstgui/uidescription/expat
./giada-1.0.0/src/deps/vst3sdk/vstgui4/vstgui/uidescription/expat/expat_external.h
./giada-1.0.0/src/deps/vst3sdk/vstgui4/vstgui/uidescription/expat/expat.h


You are receiving this mail because: