CVE-2012-1148
EPSS 0.97%Published: 7/3/2012Modified: 4/28/2026
Description
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
Affected packages (3)
- Debian/expatfrom 0, < 2.1.0~beta3-1
- Debian/libxmltokfrom 0
- Debian/xmlrpc-cfrom 0, < 1.16.33-3.2