CVE Database
/

CVE-2019-15903

Back to search

CVE-2019-15903

Published: Sep 4, 2019

Modified: May 30, 2025

PUBLISHED

Description

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-4132-1
vendor-advisory
x_refsource_UBUNTU
USN-4132-2
vendor-advisory
x_refsource_UBUNTU
FEDORA-2019-613edfe68b
vendor-advisory
x_refsource_FEDORA
DSA-4530
vendor-advisory
x_refsource_DEBIAN
FEDORA-2019-9505c6b555
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:2205
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2204
vendor-advisory
x_refsource_SUSE
FEDORA-2019-672ae0f060
vendor-advisory
x_refsource_FEDORA
USN-4165-1
vendor-advisory
x_refsource_UBUNTU
DSA-4549
vendor-advisory
x_refsource_DEBIAN
RHSA-2019:3210
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3237
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2019:2420
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2424
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2425
vendor-advisory
x_refsource_SUSE
RHSA-2019:3756
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2019:2447
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2451
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2452
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2459
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2464
vendor-advisory
x_refsource_SUSE
DSA-4571
vendor-advisory
x_refsource_DEBIAN
GLSA-201911-08
vendor-advisory
x_refsource_GENTOO
USN-4202-1
vendor-advisory
x_refsource_UBUNTU
20191211 APPLE-SA-2019-12-10-8 watchOS 6.1.1
mailing-list
x_refsource_BUGTRAQ
20191211 APPLE-SA-2019-12-10-5 tvOS 13.3
mailing-list
x_refsource_BUGTRAQ
20191213 APPLE-SA-2019-12-10-8 watchOS 6.1.1
mailing-list
x_refsource_FULLDISC
20191213 APPLE-SA-2019-12-10-5 tvOS 13.3
mailing-list
x_refsource_FULLDISC
openSUSE-SU-2020:0010
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0086
vendor-advisory
x_refsource_SUSE
USN-4335-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now