Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "10.11.0"
},
{
"last_affected": "10.11.5"
}
],
"vendor_product": "apple:mac_os_x",
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"fixed": "6.5.1"
}
],
"vendor_product": "mcafee:policy_auditor",
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:mcafee:policy_auditor:*:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"fixed": "48.0"
}
],
"vendor_product": "mozilla:firefox",
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "12.04"
},
{
"last_affected": "14.04"
},
{
"last_affected": "16.04"
}
],
"vendor_product": "canonical:ubuntu_linux",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "8.0"
}
],
"vendor_product": "debian:debian_linux",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "42.1"
}
],
"vendor_product": "opensuse:leap",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "13.1"
},
{
"last_affected": "13.2"
}
],
"vendor_product": "opensuse:opensuse",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "11-sp4"
}
],
"vendor_product": "suse:linux_enterprise_debuginfo",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "12-NA"
},
{
"last_affected": "12-sp1"
}
],
"vendor_product": "suse:linux_enterprise_desktop",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*",
"cpe:2.3:o:suse:linux_enterprise_desktop:12:sp1:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "11-sp4"
},
{
"last_affected": "12-NA"
},
{
"last_affected": "12-sp1"
}
],
"vendor_product": "suse:linux_enterprise_server",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "11-sp4"
},
{
"last_affected": "12-NA"
},
{
"last_affected": "12-sp1"
}
],
"vendor_product": "suse:linux_enterprise_software_development_kit",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*",
"cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:*",
"cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "1.3"
}
],
"vendor_product": "suse:studio_onsite",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:suse:studio_onsite:1.3:*:*:*:*:*:*:*"
]
}
]
}{
"cpe": "cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.2.0"
}
],
"source": "CPE_RANGE"
}{
"extracted_events": [
{
"introduced": "2.7.0"
},
{
"fixed": "2.7.15"
},
{
"introduced": "3.3.0"
},
{
"fixed": "3.3.7"
},
{
"introduced": "3.4.0"
},
{
"fixed": "3.4.7"
},
{
"introduced": "3.5.0"
},
{
"fixed": "3.5.4"
},
{
"introduced": "3.6.0"
},
{
"fixed": "3.6.2"
}
],
"cpe": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE"
}