CVE-2024-45490

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

History

04 Nov 2025, 17:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/09/msg00036.html -

03 Nov 2025, 23:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Dec/10 -
  • () http://seclists.org/fulldisclosure/2024/Dec/12 -
  • () http://seclists.org/fulldisclosure/2024/Dec/6 -
  • () http://seclists.org/fulldisclosure/2024/Dec/7 -
  • () http://seclists.org/fulldisclosure/2024/Dec/8 -

14 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-190

Information

Published : 2024-08-30 03:15

Updated : 2025-11-04 17:16


NVD link : CVE-2024-45490

Mitre link : CVE-2024-45490

CVE.ORG link : CVE-2024-45490


JSON object : View

Products Affected

libexpat_project

  • libexpat
CWE
CWE-611

Improper Restriction of XML External Entity Reference

CWE-190

Integer Overflow or Wraparound