CVE-2024-50602

Name
CVE-2024-50602
Description
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/libexpat/libexpat/pull/915

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* libexpat >= 0 < 2.6.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
expat edge-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.19-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.17-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.20-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.18-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.21-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed