Vulnerability CVE-2022-43680


Published: 2022-10-24

Description:
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

 References:
https://github.com/libexpat/libexpat/pull/650
https://github.com/libexpat/libexpat/pull/616
https://github.com/libexpat/libexpat/issues/649

Copyright 2025, cxsecurity.com

 

Back to Top