HIGH · 8.8

CVE-2021-45960

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memor...

Vulnerability Description

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Libexpat ProjectLibexpat< 2.4.3
TenableNessus< 8.15.3
DebianDebian Linux10.0
SiemensSinema Remote Connect Server< 3.1
NetappActive Iq Unified Manager-
NetappHci Baseboard Management Controllerh610c
NetappOncommand Workflow Automation-
NetappSolidfire \& Hci Management Node-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-45960?

CVE-2021-45960 is a vulnerability with a CVSS score of 8.8 (HIGH). In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memor...

How severe is CVE-2021-45960?

CVE-2021-45960 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-45960?

Check the references section above for vendor advisories and patch information. Affected products include: Libexpat Project Libexpat, Tenable Nessus, Debian Debian Linux, Siemens Sinema Remote Connect Server, Netapp Active Iq Unified Manager.