CVE-2019-15903
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early.
a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
HIGH · CVSS 7.5
EPSS 0.00203
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules8
YARA rules0