The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
2016-06-30T17:59:04.000
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | libexpat_project | libexpat | ≤ 2.1.1 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Application | mcafee | policy_auditor | < 6.5.1 | Yes |
Application | python | python | < 2.7.15 | Yes |
Application | python | python | < 3.3.7 | Yes |
Application | python | python | < 3.4.7 | Yes |
Application | python | python | < 3.5.4 | Yes |
Application | python | python | < 3.6.2 | Yes |