Description
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 11 | | =2.2.10-2 || =2.2.10-2+deb11u1 || =2.2.10-2+deb11u2 || =2.2.10-2+deb11u3 || =2.2.10-2+deb11u4 || =2.2.10-2+deb11u5 || =2.2.10-2+deb11u6 || =2.2.10-2+deb11u7 || =2.3.0-1 || =2.4.1-1 || =2.4.1-2 || =2.4.1-3 || =2.4.2-1 || =2.4.3-1 || =2.4.3-2 || =2.4.3-3 || =2.4.4-1 || =2.4.5-1 || =2.4.5-2 || =2.4.6-1 || =2.4.7-1 || =2.4.8-1 || =2.4.8-2 || =2.4.9-1 || =2.5.0-1 || =2.5.0-2 || =2.6.0-1 || =2.6.1-1 || =2.6.1-2 || =2.6.2-1 || =2.6.2-2 || =2.6.3-1 || =2.6.3-2 || =2.6.4-1 || =2.7.0-1 || =2.7.1-1 || =2.7.1-2 || =2.7.2-1 || =2.7.3-1 || =2.7.3-2 || =2.7.4-1 || =2.7.5-1 || =2.8.0-1 || =2.8.0-2 || =2.8.1-1 || =2.8.2-1 || =2.8.2-1~deb13u1 || =2.8.3-1 || =2.8.3-1~deb13u1 |
 debian 12 | | =2.5.0-1 || =2.5.0-1+deb12u1 || =2.5.0-1+deb12u2 || =2.5.0-2 || =2.6.0-1 || =2.6.1-1 || =2.6.1-2 || =2.6.2-1 || =2.6.2-2 || =2.6.3-1 || =2.6.3-2 || =2.6.4-1 || =2.7.0-1 || =2.7.1-1 || =2.7.1-2 || =2.7.2-1 || =2.7.3-1 || =2.7.3-2 || =2.7.4-1 || =2.7.5-1 || =2.8.0-1 || =2.8.0-2 || =2.8.1-1 || =2.8.2-1 || =2.8.2-1~deb13u1 || =2.8.3-1 || =2.8.3-1~deb13u1 |
 debian 13 | | =2.7.1-2 || =2.7.2-1 || =2.7.3-1 || =2.7.3-2 || =2.7.4-1 || =2.7.5-1 || =2.8.0-1 || =2.8.0-2 || =2.8.1-1 || =2.8.2-1 || =2.8.2-1~deb13u1 || =2.8.3-1 || =2.8.3-1~deb13u1 |
 debian 14 | | =2.7.1-2 || =2.7.2-1 || =2.7.3-1 || =2.7.3-2 || =2.7.4-1 || =2.7.5-1 || =2.8.0-1 || =2.8.0-2 || =2.8.1-1 || =2.8.2-1 || =2.8.2-1~deb13u1 || =2.8.3-1 || =2.8.3-1~deb13u1 |