readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Nov 8, 2019 | Jul 3, 2012 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Mar 24, 2017 | Jul 3, 2012 |
| Apple Osx Libexpat | — | Upgrade macOS to the latest version | Mar 29, 2016 | Jul 3, 2012 |
| Debian | — | No solution exists | May 30, 2025 | May 30, 2025 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Oct 30, 2017 | Jul 3, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 3, 2012 |
| Suse | — | Upgrade expatUpgrade libexpat1-32bitUpgrade libexpat1-x86Upgrade libexpat-develUpgrade libexpat1 | Dec 12, 2013 | Jun 27, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub