DEBIAN-CVE-2021-45960

Source
https://security-tracker.debian.org/tracker/CVE-2021-45960
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-45960.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2021-45960
Upstream
Published
2022-01-01T19:15:08Z
Modified
2025-09-25T23:25:40.674938Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

References

Affected packages

Debian:11

expat

Package

Name
expat
Purl
pkg:deb/debian/expat?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.10-2+deb11u1

Affected versions

2.*

2.2.10-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

libxmltok

Package

Name
libxmltok
Purl
pkg:deb/debian/libxmltok?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2-4
1.2-4.1~exp1
1.2-4.1
1.2-4.2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12

expat

Package

Name
expat
Purl
pkg:deb/debian/expat?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

libxmltok

Package

Name
libxmltok
Purl
pkg:deb/debian/libxmltok?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2-4
1.2-4.1~exp1
1.2-4.1
1.2-4.2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13

expat

Package

Name
expat
Purl
pkg:deb/debian/expat?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14

expat

Package

Name
expat
Purl
pkg:deb/debian/expat?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}