IM
IronMonkey Threat Research

CVE-2021-45960 HIGH

Published: 2022-01-01 | Last Modified: 2025-05-05 | Status: Modified

Description

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

Additional Descriptions (1)

En Expat (también se conoce como libexpat) versiones anteriores a 2.4.3, un desplazamiento a la izquierda por 29 (o más) lugares en la función storeAtts en el archivo xmlparse.c puede conllevar a un comportamiento incorrecto de reasignación (por ejemplo, asignar muy pocos bytes, o sólo liberar memoria).

CVSS Metrics

Base Score: 8.8 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 5.9

Base Score: 9.0 (HIGH)

AV:N/AC:L/Au:S/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityLOW
AuthenticationSINGLE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 8.0

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-682
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-682

Affected Products

Vendor Product Version Update Type
libexpat_project libexpat * <built-in method update of dict object at 0x72a9af821180> Application
tenable nessus * <built-in method update of dict object at 0x72a9e6d11c00> Application
tenable nessus * <built-in method update of dict object at 0x72a9cc848c00> Application
debian debian_linux 10.0 <built-in method update of dict object at 0x72a9e4187d00> Operating System
debian debian_linux 11.0 <built-in method update of dict object at 0x72a9af822680> Operating System
siemens sinema_remote_connect_server * <built-in method update of dict object at 0x72a9b0d8db40> Application
netapp active_iq_unified_manager - <built-in method update of dict object at 0x72a9cc84a040> Application
netapp hci_baseboard_management_controller h610c <built-in method update of dict object at 0x72a9cc121b40> Application
netapp hci_baseboard_management_controller h610s <built-in method update of dict object at 0x72a9990f0d00> Application
netapp hci_baseboard_management_controller h615c <built-in method update of dict object at 0x72a9af823100> Application
netapp oncommand_workflow_automation - <built-in method update of dict object at 0x72a9cc38c800> Application
netapp solidfire_\&_hci_management_node - <built-in method update of dict object at 0x72a9cc121b80> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Yes cpe:2.3:a:netapp:hci_baseboard_management_controller:h610c:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:hci_baseboard_management_controller:h610s:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:hci_baseboard_management_controller:h615c:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*

References

Notification
Message here