In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
[
{
"id": "CVE-2018-20843-74406d59",
"signature_type": "Function",
"digest": {
"length": 670.0,
"function_hash": "10718674393994758979083102855553023681"
},
"target": {
"file": "expat/tests/runtests.c",
"function": "START_TEST"
},
"source": "https://github.com/libexpat/libexpat/commit/d3b78b42a2dcdea98e22625cfff67a49d47e6025",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2018-20843-ee80e572",
"signature_type": "Line",
"digest": {
"line_hashes": [
"70970158302216444732948686873374648009",
"197734145770944038326200234670765972062",
"333002349092091346504095730741649465004",
"132190683235044997527211951942674695301"
],
"threshold": 0.9
},
"target": {
"file": "expat/tests/runtests.c"
},
"source": "https://github.com/libexpat/libexpat/commit/d3b78b42a2dcdea98e22625cfff67a49d47e6025",
"signature_version": "v1",
"deprecated": false
}
]