CVE-2024-45490

Name
CVE-2024-45490
Description
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/libexpat/libexpat/pull/890
https://github.com/libexpat/libexpat/issues/887
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20241018-0004/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* libexpat >= None < 2.6.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status