Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-expat | Sep 20, 2017 | Jun 16, 2016 | |
| Apple Itunes | apple-itunes-upgrade-latest | Mar 24, 2017 | Jun 16, 2016 | |
| Debian | debian-upgrade-expat | Jun 7, 2016 | Jun 7, 2016 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | Sep 6, 2016 | |
| Freebsd | freebsd-upgrade-package-expat | Dec 10, 2025 | Jun 9, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-libs-expat | Oct 30, 2017 | Jun 16, 2016 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-xulrunner | Jun 17, 2020 | Jun 16, 2016 | |
| Suse | — | suse-upgrade-expatsuse-upgrade-expat-debuginfosuse-upgrade-expat-debuginfo-32bitsuse-upgrade-expat-debugsourcesuse-upgrade-libexpat-develsuse-upgrade-libexpat-devel-32bitsuse-upgrade-libexpat1suse-upgrade-libexpat1-32bitsuse-upgrade-libexpat1-debuginfosuse-upgrade-libexpat1-debuginfo-32bitsuse-upgrade-libexpat1-x86 | Apr 26, 2018 | Jun 16, 2016 |
| Ubuntu | ubuntu-upgrade-lib64expat1ubuntu-upgrade-libexpat1ubuntu-upgrade-libxmlrpc-c-4ubuntu-upgrade-libxmlrpc-core-c3 | Jun 20, 2016 | Jun 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub