Commit Graph

4 Commits

Author SHA1 Message Date
Rob Crittenden
288e29745d Prevent integer overflow or wraparound CVE-2024-45491
An issue was discovered in libexpat before 2.6.3. dtdCopy in
xmlparse.c can have an integer overflow for nDefaultAtts on
32-bit platforms (where UINT_MAX equals SIZE_MAX).

Backported from upstream https://github.com/libexpat/libexpat/pull/891

Resolves: RHEL-57519
2024-09-20 10:04:54 -04:00
Rob Crittenden
0e89150eee expat: Address segementation fault in CVE-2023-52425
CVE-2023-52425 is a DoS where extremely large tags can cause
significant processing delays. It isn't reasonably possible to
backport the fix but while testing the impact it was determined
that a large ctags could cause a segmentation fault. That is what
is addressed.

Resolves: RHEL-24226
2024-04-25 10:47:50 -04:00
James Antill
32dbac7946 Auto sync2gitlab import of xmlrpc-c-1.51.0-8.el8.src.rpm 2022-05-31 15:02:30 -04:00
James Antill
bed8a35791 Auto sync2gitlab import of xmlrpc-c-1.51.0-5.el8.src.rpm 2022-05-26 16:18:32 -04:00