Home
MEDIUM: 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:LDefault status
unaffected
Any version before 2.7.4
affected
Description
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Problem types
CWE-190 Integer Overflow or Wraparound
Product status
Any version before 2.7.4
References
github.com/libexpat/libexpat/pull/1075
github.com/...mmits/9c2d990389e6abe2e44527eeaa8b39f16fe859c7