An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
On 32-bit platforms, where UINT_MAX equals SIZE_MAX, the dtdCopy function during the copying of DTD definitions can cause an integer overflow for the nDefaultAtts variable. This overflow can result in incorrect calculation of allocated memory size, which consequently leads to memory corruption of the process handling XML data.
An attacker can remotely, without authentication, cause arbitrary code execution (RCE), disclosure of sensitive data, or denial of service (DoS) in an application using a vulnerable version of the libexpat library.
The libexpat library should be updated to version 2.6.3 or later. Users of Debian distribution and NetApp and Siemens systems should apply patches available in the appropriate distribution channels according to vendor references.
Libexpat (libexpat Project) in versions before 2.6.3, running on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLibexpat Project Libexpat
APPLibexpat Project< 2.6.3
Related vulnerabilities
Integer overflow w libexpat — podatność w nextScaffoldPart na platformach 32-bitowych
Integer overflow w libexpat (storeRawNames) — RCE bez uwierzytelnienia
Brak walidacji kodowania UTF-8 w bibliotece Expat (libexpat)
Wstrzykiwanie separatorów przestrzeni nazw w Expat (libexpat) przed 2.4.5
Przepełnienie liczby całkowitej w Libexpat (XML_GetBuffer) — CVE-2022-23852