Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Vulnerability: CVE-2024-45492 in Alpine 3.20.2 #416

Open
norakf opened this issue Sep 6, 2024 · 0 comments
Open

Critical Vulnerability: CVE-2024-45492 in Alpine 3.20.2 #416

norakf opened this issue Sep 6, 2024 · 0 comments

Comments

@norakf
Copy link

norakf commented Sep 6, 2024

Getting the following issue when using alpine 3.20.2:
Vulnerability Overview

CVE:
Package: libexpat
Installed Version: 2.6.2-r0
Vulnerability CVE-2024-45492
Severity: CRITICAL
Fixed Version: 2.6.3-r0
Link: CVE-2024-45492

Vulnerability Description :
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

Is there a plan to fix this vulnerability in the next version?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant