CVE-2024-50602

Name
CVE-2024-50602
Description
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/libexpat/libexpat/pull/915
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20250404-0008/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/04/msg00040.html

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* active_iq_unified_manager == None == -
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* solidfire_\&_hci_management_node == None == -
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:* solidfire_\&_hci_storage_node == None == -
cpe:2.3:a:netapp:windows_host_utilities:-:*:*:*:*:*:*:* windows_host_utilities == None == -
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* debian_linux == None == 11.0
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* hci_compute_node == None == -

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
qt6-qtwebengine edge-community 6.8.3-r1 Bart Ribbers <bribbers@disroot.org> fixed
qt6-qtwebengine 3.22-community 6.8.3-r1 Bart Ribbers <bribbers@disroot.org> fixed
expat edge-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.22-main 2.6.4-r0 None fixed
expat 3.21-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.20-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.19-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.18-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.17-main 2.6.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed