Back to search
CVE-2018-20843
Published: Jun 24, 2019
Modified: May 30, 2025
PUBLISHED
Description
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-4040-1
vendor-advisory
x_refsource_UBUNTU
USN-4040-2
vendor-advisory
x_refsource_UBUNTU
DSA-4472
vendor-advisory
x_refsource_DEBIAN
20190628 [SECURITY] [DSA 4472-1] expat security update
mailing-list
x_refsource_BUGTRAQ
[debian-lts-announce] 20190629 [SECURITY] [DLA 1839-1] expat security update
mailing-list
x_refsource_MLIST
FEDORA-2019-18868e1715
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-139fcda84d
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:1777
vendor-advisory
x_refsource_SUSE
GLSA-201911-08
vendor-advisory
x_refsource_GENTOO
https://www.oracle.com/security-alerts/cpuapr2020.html
x_refsource_MISC
https://www.oracle.com/security-alerts/cpuoct2020.html
x_refsource_MISC
https://github.com/libexpat/libexpat/issues/186
x_refsource_MISC
https://github.com/libexpat/libexpat/pull/262
x_refsource_MISC
https://github.com/libexpat/libexpat/blob/R_2_2_7/expat/Changes
x_refsource_MISC
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5226
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20190703-0001/
x_refsource_CONFIRM
https://support.f5.com/csp/article/K51011533
x_refsource_CONFIRM
https://www.oracle.com/security-alerts/cpuApr2021.html
x_refsource_MISC
https://www.oracle.com/security-alerts/cpuoct2021.html
x_refsource_MISC
https://www.tenable.com/security/tns-2021-11
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now