src
src copied to clipboard
CVE-2024-45490 (Critical) detected in src3.1.5
CVE-2024-45490 - Critical Severity Vulnerability
Vulnerable Library - src3.1.5
MidnightBSD OS source code
Library home page: https://github.com/MidnightBSD/src.git
Found in HEAD commit: 816463d989cc5839c1cca2efb5bf2503408507fb
Found in base branches: stable/3.2, master
Vulnerable Source Files (1)
/contrib/expat/lib/xmlparse.c
Vulnerability Details
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
Publish Date: 2024-08-30
URL: CVE-2024-45490
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2024-45490
Release Date: 2024-08-30
Fix Resolution: R_2_6_3
Step up your Open Source Security Game with Mend here