CVE-2021-45960

HIGH8.8EPSS 0.32%

expat - security update

發布日:2022/1/1修改日:2025/12/3
也稱為:ALPINE-CVE-2021-45960

描述

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(2)