SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-45960

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

HIGH 8.8EPSS 4.23%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
4.23% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-682
Affected
libexpat project/libexpat · tenable/nessus · debian/debian linux · siemens/sinema remote connect server · netapp/active iq unified manager · netapp/hci baseboard management controller · netapp/oncommand workflow automation · netapp/solidfire \& hci management node
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.