CVE-2024-50602
Published Oct 27, 2024An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
Vendor/product archive
2 CVEs tagged to netapp / windows_host_utilities — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).