CVE-2016-4472
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.95% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- libexpat project/libexpat · canonical/ubuntu linux · mcafee/policy auditor · python/python
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/91528Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3013-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1344251Issue Tracking, Patch, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365Third Party Advisory
- https://security.gentoo.org/glsa/201701-21Third Party Advisory
- https://sourceforge.net/p/expat/code_git/ci/f0bec73b018caa07d3e75ec8dd967f3785d71bdePatch, Third Party Advisory
- https://www.tenable.com/security/tns-2016-20Third Party Advisory
- http://www.securityfocus.com/bid/91528Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3013-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1344251Issue Tracking, Patch, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365Third Party Advisory
- https://security.gentoo.org/glsa/201701-21Third Party Advisory
- https://sourceforge.net/p/expat/code_git/ci/f0bec73b018caa07d3e75ec8dd967f3785d71bdePatch, Third Party Advisory
- https://www.tenable.com/security/tns-2016-20Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.