Out-of-bounds read in expat - CVE-2019-15903

 

Out-of-bounds read in expat - CVE-2019-15903

Published: September 12, 2019 / Updated: November 20, 2024


Vulnerability identifier: #VU21091
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15903
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing XML documents within the expat library. A remote attacker can create a specially crafted XML file, pass it to the affected application, trigger out-of-bounds read error and read contents of memory on the system or crash the affected application.


Affected software

expat
Amazon Linux AMI
Gentoo Linux
Arch Linux
F5OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Slackware Linux
SUSE Linux
Opensuse
Ubuntu
Fedora
Brocade Fabric OS
HPE B-series SN6750B Fibre Channel Switch
HPE B-series SN6700B Fibre Channel Switch
HPE B-series SN6650B Fibre Channel Switch
HPE B-series SN6600B Fibre Channel Switch
HPE B-series SN4700B SAN Extension Switch
HPE B-series SN3600B Fibre Channel Switch
HPE B-series SN2600B SAN Extension Switch
HPE SN8600B 8-slot SAN Director Switch
HPE SN8600B 4-slot SAN Director Switch
HPE SN8700B 8-slot SAN Director Switch
HPE SN8700B 4-slot SAN Director Switch
Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy
BIG-IP
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Data Computing Appliance (DCA)
Ansible Automation Platform
Tenable Nessus
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
expat (Red Hat package)
expat (Debian package)
jbcs-httpd24-httpd (Red Hat package)
python2-tkinter (Alpine package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
firefox (Ubuntu package)
thunderbird (Ubuntu package)
thunderbird (Debian package)
firefox-esr (Debian package)
firefox (Alpine package)
firefox-esr (Alpine package)
libxmltok1t64 (Ubuntu package)
libxmltok1 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
expat (Ubuntu package)
expat
Traffix SDC
VMware Horizon Client
Red Hat OpenShift Container Platform
BIG-IQ Centralized Management
Oracle Outside In Technology
NetWorker Management Console
Cisco Jabber
Mozilla Thunderbird
Cisco Webex Meetings
Firefox ESR
Mozilla Firefox
Google Chrome

How to mitigate CVE-2019-15903

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

expat - update to 2.2.8
BIG-IP - addressed in versions 14.1.4.5, 15.1.4.1, 16.1.2
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-3.jbcs.el6, 1.15.7-3.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-25.jbcs.el6, 1.39.2-25.jbcs.el7
expat (Red Hat package) - addressed in versions 2.1.0-12.el7, 2.2.5-4.el8
expat (Debian package) - addressed in versions 2.2.0-2+deb9u3, 2.2.6-2+deb10u1
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-57.jbcs.el6, 2.4.37-57.jbcs.el7
python2-tkinter (Alpine package) - update to 2.7.17-r0
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-51.GA.jbcs.el6, 2.9.2-51.GA.jbcs.el7
Quay - update to 3.3.3
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.64.1-36.jbcs.el6, 7.64.1-36.jbcs.el7
Tenable Nessus - update to 8.15.0
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
firefox (Ubuntu package) - addressed in versions 70.0+build2-0ubuntu0.16.04.1, 70.0+build2-0ubuntu0.18.04.1, 70.0+build2-0ubuntu0.19.04.1, 70.0+build2-0ubuntu0.19.10.1
thunderbird (Ubuntu package) - addressed in versions 1:68.2.1+build1-0ubuntu0.18.04.1, 1:68.2.1+build1-0ubuntu0.19.10.1, 1:68.2.2+build1-0ubuntu0.18.04.1, 1:68.2.2+build1-0ubuntu0.19.10.1, 1:68.7.0+build1-0ubuntu0.16.04.2
thunderbird (Debian package) - addressed in versions 1:68.2.2-1~deb9u1, 1:68.2.2-1~deb10u1
Firefox ESR - update to 68.2.0
Mozilla Firefox - update to 70.0
Mozilla Thunderbird - update to 68.2.0
firefox-esr (Debian package) - update to 68.2.0esr-1~deb10u1
firefox (Alpine package) - update to 72.0.1-r0
firefox-esr (Alpine package) - update to 68.2.0-r0
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libxmltok1t64 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2-4.1ubuntu3.1
libxmltok1 (Ubuntu package) - update to Ubuntu Pro
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-7.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-24.jbcs.el6, 2.0.8-24.jbcs.el7
expat (Ubuntu package) - addressed in versions 2.1.0-7ubuntu0.16.04.5, 2.2.5-3ubuntu0.2, 2.2.6-1ubuntu0.19.5
expat - addressed in versions 2.2.8-1.fc29, 2.2.8-1.fc30, 2.2.8-1.fc31
Red Hat OpenShift Container Platform - update to 4.3.40
Brocade Fabric OS - addressed in versions 9.1.1d2, 9.2.0b1, 9.2.1
NetWorker Management Console - update to 19.12.0.1
Google Chrome - update to 78.0.3904.70

External References

Related Security Bulletins