CVE-2019-15903
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecu… (CVE-2019-15903)
highEPSS 6.6%
Description
Metrics
Severity
high
93.56
no public PoC known
7.5
93.5 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2019-09-04 05:59 UTC
—
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
libexpat_project
libexpat2.2.8
python
python2.7.0 – 2.7.17
python
python3.5.0 – 3.5.8
python
python3.6.0 – 3.6.10
python
python3.7.0 – 3.7.5
References & sources
- https://usn.ubuntu.com/4132-1/vendor-advisoryx_refsource_UBUNTU
- https://seclists.org/bugtraq/2019/Sep/30mailing-listx_refsource_BUGTRAQ
- https://usn.ubuntu.com/4132-2/vendor-advisoryx_refsource_UBUNTU
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BDUTI5TVQWIGGQXPEVI4T2ENHFSBMIBP/vendor-advisoryx_refsource_FEDORA
- https://www.debian.org/security/2019/dsa-4530vendor-advisoryx_refsource_DEBIAN
- https://seclists.org/bugtraq/2019/Sep/37mailing-listx_refsource_BUGTRAQ
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA/vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00081.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00080.htmlvendor-advisoryx_refsource_SUSE
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S26LGXXQ7YF2BP3RGOWELBFKM6BHF6UG/vendor-advisoryx_refsource_FEDORA
- https://seclists.org/bugtraq/2019/Oct/29mailing-listx_refsource_BUGTRAQ
- https://usn.ubuntu.com/4165-1/vendor-advisoryx_refsource_UBUNTU
- https://www.debian.org/security/2019/dsa-4549vendor-advisoryx_refsource_DEBIAN
- https://access.redhat.com/errata/RHSA-2019:3210vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3237vendor-advisoryx_refsource_REDHAT
- https://seclists.org/bugtraq/2019/Nov/1mailing-listx_refsource_BUGTRAQ
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00000.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00002.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00003.htmlvendor-advisoryx_refsource_SUSE
- https://access.redhat.com/errata/RHSA-2019:3756vendor-advisoryx_refsource_REDHAT
IDCVE-2019-15903