Out-of-bounds read in expat - CVE-2019-15903
Published: September 12, 2019 / Updated: November 20, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing XML documents within the expat library. A remote attacker can create a specially crafted XML file, pass it to the affected application, trigger out-of-bounds read error and read contents of memory on the system or crash the affected application.
Affected software
Amazon Linux AMI
Gentoo Linux
Arch Linux
F5OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Slackware Linux
SUSE Linux
Opensuse
Ubuntu
Fedora
Brocade Fabric OS
HPE B-series SN6750B Fibre Channel Switch
HPE B-series SN6700B Fibre Channel Switch
HPE B-series SN6650B Fibre Channel Switch
HPE B-series SN6600B Fibre Channel Switch
HPE B-series SN4700B SAN Extension Switch
HPE B-series SN3600B Fibre Channel Switch
HPE B-series SN2600B SAN Extension Switch
HPE SN8600B 8-slot SAN Director Switch
HPE SN8600B 4-slot SAN Director Switch
HPE SN8700B 8-slot SAN Director Switch
HPE SN8700B 4-slot SAN Director Switch
Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy
BIG-IP
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Data Computing Appliance (DCA)
Ansible Automation Platform
Tenable Nessus
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
expat (Red Hat package)
expat (Debian package)
jbcs-httpd24-httpd (Red Hat package)
python2-tkinter (Alpine package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
firefox (Ubuntu package)
thunderbird (Ubuntu package)
thunderbird (Debian package)
firefox-esr (Debian package)
firefox (Alpine package)
firefox-esr (Alpine package)
libxmltok1t64 (Ubuntu package)
libxmltok1 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
expat (Ubuntu package)
expat
Traffix SDC
VMware Horizon Client
Red Hat OpenShift Container Platform
BIG-IQ Centralized Management
Oracle Outside In Technology
NetWorker Management Console
Cisco Jabber
Mozilla Thunderbird
Cisco Webex Meetings
Firefox ESR
Mozilla Firefox
Google Chrome
How to mitigate CVE-2019-15903
BIG-IP - addressed in versions 14.1.4.5, 15.1.4.1, 16.1.2
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-3.jbcs.el6, 1.15.7-3.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-25.jbcs.el6, 1.39.2-25.jbcs.el7
expat (Red Hat package) - addressed in versions 2.1.0-12.el7, 2.2.5-4.el8
expat (Debian package) - addressed in versions 2.2.0-2+deb9u3, 2.2.6-2+deb10u1
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-57.jbcs.el6, 2.4.37-57.jbcs.el7
python2-tkinter (Alpine package) - update to 2.7.17-r0
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-51.GA.jbcs.el6, 2.9.2-51.GA.jbcs.el7
Quay - update to 3.3.3
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.64.1-36.jbcs.el6, 7.64.1-36.jbcs.el7
Tenable Nessus - update to 8.15.0
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
firefox (Ubuntu package) - addressed in versions 70.0+build2-0ubuntu0.16.04.1, 70.0+build2-0ubuntu0.18.04.1, 70.0+build2-0ubuntu0.19.04.1, 70.0+build2-0ubuntu0.19.10.1
thunderbird (Ubuntu package) - addressed in versions 1:68.2.1+build1-0ubuntu0.18.04.1, 1:68.2.1+build1-0ubuntu0.19.10.1, 1:68.2.2+build1-0ubuntu0.18.04.1, 1:68.2.2+build1-0ubuntu0.19.10.1, 1:68.7.0+build1-0ubuntu0.16.04.2
thunderbird (Debian package) - addressed in versions 1:68.2.2-1~deb9u1, 1:68.2.2-1~deb10u1
Firefox ESR - update to 68.2.0
Mozilla Firefox - update to 70.0
Mozilla Thunderbird - update to 68.2.0
firefox-esr (Debian package) - update to 68.2.0esr-1~deb10u1
firefox (Alpine package) - update to 72.0.1-r0
firefox-esr (Alpine package) - update to 68.2.0-r0
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libxmltok1t64 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2-4.1ubuntu3.1
libxmltok1 (Ubuntu package) - update to Ubuntu Pro
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-7.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-24.jbcs.el6, 2.0.8-24.jbcs.el7
expat (Ubuntu package) - addressed in versions 2.1.0-7ubuntu0.16.04.5, 2.2.5-3ubuntu0.2, 2.2.6-1ubuntu0.19.5
expat - addressed in versions 2.2.8-1.fc29, 2.2.8-1.fc30, 2.2.8-1.fc31
Red Hat OpenShift Container Platform - update to 4.3.40
Brocade Fabric OS - addressed in versions 9.1.1d2, 9.2.0b1, 9.2.1
NetWorker Management Console - update to 19.12.0.1
Google Chrome - update to 78.0.3904.70
External References
Related Security Bulletins
- Buffer overflow in libexpat
- Ubuntu update for Expat
- Slackware Linux update for expat
- Debian update for expat
- OpenSUSE Linux update for expat
- OpenSUSE Linux update for expat
- Slackware Linux update for python
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Firefox ESR
- Slackware Linux update for mozilla-firefox
- Multiple vulnerabilities in Google Chrome
- Multiple vulnerabilities in Mozilla Thunderbird
- Ubuntu update for Firefox
- Debian update for firefox-esr
- Arch Linux update for chromium
- Arch Linux update for firefox
- Arch Linux update for thunderbird
- Red Hat update for thunderbird
- Red Hat update for thunderbird
- OpenSUSE Linux update for chromium, re2
- OpenSUSE Linux update for chromium, re2
- OpenSUSE Linux update for chromium, re2
- Red Hat update for thunderbird
- OpenSUSE update for Mozilla Thunderbird
- OpenSUSE update for Mozilla Thunderbird
- OpenSUSE Linux update for MozillaFirefox, MozillaFirefox-branding-SLE
- OpenSUSE Linux update for MozillaFirefox, MozillaFirefox-branding-SLE
- Debian update for thunderbird
- Gentoo update for Expat
- Ubuntu update for Thunderbird
- Ubuntu update for Thunderbird
- OpenSUSE Linux update for chromium, re2
- Ubuntu update for Thunderbird
- Multiple vulnerabilities in Oracle Outside In Technology
- Red Hat update for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP3
- Out-of-bounds read in firefox (Alpine package)
- Out-of-bounds read in python2-tkinter (Alpine package)
- Out-of-bounds read in firefox-esr (Alpine package)
- Red Hat Enterprise Linux 7 update for expat
- Red Hat Enterprise Linux 8 update for expat
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Amazon Linux AMI update for expat
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Amazon Linux AMI update for expat
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Tenable Nessus
- Denial of service in F5 BIG-IP (Expat library)
- Denial of service in BIG-IQ Centralized Management (Expat library)
- Denial of service in Traffix SDC (Expat library)
- Denial of service in F5OS (Expat library)
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in HPE Brocade Fabric OS
- Ubuntu update for libxmltok
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3
- Fedora 30 update for expat
- Fedora 29 update for expat
- Fedora 31 update for expat
- Dell NetWorker Management Console update for third-party components