Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Aug 30, 2017 | Jul 3, 2012 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Mar 24, 2017 | Jul 3, 2012 |
| Apple Osx Libexpat | — | Upgrade macOS to the latest version | Mar 29, 2016 | Jul 3, 2012 |
| Centos_linux | — | Upgrade expat-develUpgrade expat | Dec 1, 2016 | Jul 3, 2012 |
| Debian | — | Upgrade xmlrpc-cUpgrade expat | Jul 30, 2024 | Jul 3, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 11, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Oct 30, 2017 | Jul 3, 2012 |
| Ibm Http_server | — | Apply IBM HTTP Server Interim Fix PI73984Apply IBM HTTP Server version 7.0.0.43 or laterApply IBM HTTP Server version 9.0.0.2 or laterApply IBM HTTP Server version 8.0.0.13 or laterApply IBM HTTP Server version 8.5.5.11 or later | Sep 7, 2022 | Sep 7, 2022 |
| Oracle Solaris | — | Upgrade library/expat to version 2.0.1-0.175.0.11.0.4.0 on Solaris 11.0 | May 29, 2017 | Jul 3, 2012 |
| Oracle_linux | — | Upgrade expatUpgrade expat-devel | Oct 16, 2024 | Mar 3, 2012 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Mar 3, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 3, 2012 |
| Suse | — | Upgrade libexpat1-x86Upgrade libexpat-develUpgrade libexpat1Upgrade expatUpgrade libexpat1-32bit | Dec 12, 2013 | Jun 27, 2013 |
| Ubuntu | — | Upgrade lib64expat1Upgrade libexpat1Upgrade libxmltok1 (Ubuntu Pro)Upgrade libxmltok1t64 (Ubuntu Pro)Upgrade python2.5-minimalUpgrade python2.5Upgrade python2.4-minimalUpgrade libxmltok1t64Upgrade python2.4Upgrade libexpat1-udeb | Mar 22, 2023 | Jul 3, 2012 |
| Vmsa 2012 0016 | — | Upgrade VMware ESX 4.1 to build number 874690 | Nov 22, 2012 | Jul 3, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub