CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-45491

CVSS 9.8v3.1pub. 2024-08-30upd. 2026-05-12

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

🤖 AI Analysis
How it works

On 32-bit platforms, where UINT_MAX equals SIZE_MAX, the dtdCopy function during the copying of DTD definitions can cause an integer overflow for the nDefaultAtts variable. This overflow can result in incorrect calculation of allocated memory size, which consequently leads to memory corruption of the process handling XML data.

Impact

An attacker can remotely, without authentication, cause arbitrary code execution (RCE), disclosure of sensitive data, or denial of service (DoS) in an application using a vulnerable version of the libexpat library.

Mitigation & patch

The libexpat library should be updated to version 2.6.3 or later. Users of Debian distribution and NetApp and Siemens systems should apply patches available in the appropriate distribution channels according to vendor references.

Who is affected

Libexpat (libexpat Project) in versions before 2.6.3, running on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Libexpat Project Libexpat

    APP
    Libexpat Project
    < 2.6.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-45492CRITICAL9.8PL ✓same product

Integer overflow w libexpat — podatność w nextScaffoldPart na platformach 32-bitowych

CVE-2022-25315CRITICAL9.8PL ✓same product

Integer overflow w libexpat (storeRawNames) — RCE bez uwierzytelnienia

CVE-2022-25235CRITICAL9.8PL ✓same product

Brak walidacji kodowania UTF-8 w bibliotece Expat (libexpat)

CVE-2022-25236CRITICAL9.8PL ✓same product

Wstrzykiwanie separatorów przestrzeni nazw w Expat (libexpat) przed 2.4.5

CVE-2022-23852CRITICAL9.8PL ✓same product

Przepełnienie liczby całkowitej w Libexpat (XML_GetBuffer) — CVE-2022-23852