Total vulnerabilities in the database
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Software | From | Fixed in |
---|---|---|
libexpat_project / libexpat | - | 2.4.9.x |
debian / debian_linux | 10.0 | 10.0.x |
debian / debian_linux | 11.0 | 11.0.x |
fedoraproject / fedora | 35 | 35.x |
fedoraproject / fedora | 36 | 36.x |
fedoraproject / fedora | 37 | 37.x |