Bugzilla – Bug 1219561
VUL-0: CVE-2023-52426: expat: recursive XML Entity Expansion if XML_DTD is undefined at compile time.
Last modified: 2024-07-03 12:08:34 UTC
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52426 https://www.cve.org/CVERecord?id=CVE-2023-52426 https://cwe.mitre.org/data/definitions/776.html https://github.com/libexpat/libexpat/commit/0f075ec8ecb5e43f8fdca5182f8cca4703da0404 Patch: https://github.com/libexpat/libexpat/pull/777
Tracking as affected: - SUSE:ALP:Source:Standard:1.0 - SUSE:Carwos:1 - SUSE:SLE-12:Update - SUSE:SLE-15-SP4:Update - SUSE:SLE-15:Update - openSUSE:Factory - SUSE:SLE-11:Update only on reactive support
Factory was already fixed here: * https://build.opensuse.org/request/show/1146280