RHSA-2016:2824

Affecting expat package, versions <0:2.1.0-10.el7_3

Report new vulnerabilities
medium severity
Do your applications use this vulnerable package? Test your applications

Overview

Expat is a C library for parsing XML documents. Security Fix(es): * An out-of-bounds read flaw was found in the way Expat processed certain input. A remote attacker could send specially crafted XML that, when parsed by an application using the Expat library, would cause that application to crash or, possibly, execute arbitrary code with the permission of the user running the application. (CVE-2016-0718) Red Hat would like to thank Gustavo Grieco for reporting this issue.

CVE
RHSA-2016:2824
Snyk ID
SNYK-CENTOS7-EXPAT-357962
Published
27 Jun, 2018