UBUNTU-CVE-2018-20843
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-20843
UBUNTU-CVE-2018-20843
Summary:
Details: In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
References: https://ubuntu.com/security/CVE-2018-20843, https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5226, https://github.com/libexpat/libexpat/pull/262, https://github.com/libexpat/libexpat/blob/R_2_2_7/expat/Changes, https://github.com/libexpat/libexpat/pull/262/commits/11f8838bf99ea0a6f0b76f9760c43704d00c4ff6, https://ubuntu.com/security/notices/USN-4040-1, https://ubuntu.com/security/notices/USN-4040-2, https://ubuntu.com/security/notices/USN-5455-1, https://ubuntu.com/security/notices/USN-4852-1, https://www.cve.org/CVERecord?id=CVE-2018-20843, https://ubuntu.com/security/notices/USN-7199-1
Affected packages
Package
Name: expat
Purl: pkg:deb/ubuntu/expat?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
