Integer overflow in expat - CVE-2024-45491

 

Integer overflow in expat - CVE-2024-45491

Published: September 5, 2024 / Updated: May 20, 2025


Vulnerability identifier: #VU96898
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45491
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the dtdCopy() function in xmlparse.c. A remote attacker can pass specially crafted input to the application, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

expat
Oracle Linux
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
IBM AIX
OpenBSD
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Ubuntu
Slackware Linux
Basesystem Module
Desktop Applications Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Fedora
IBM Concert Software
Cryostat
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Security Guardium Key Lifecycle Manager (GKLM)
Tenable Nessus
IBM Security Verify Governance
IBM Netezza Analytics for NPS
Service Interconnect
Data Lakehouse
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
App Connect Enterprise Certified Container
OpenShift Logging
IBM Observability with Instana
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
Precision 7920 XL Rack
Precision 7920 Rack
Storage Defender - Resiliency Service
IBM OpenPages with Watson
IBM Engineering Requirements Management DOORS Next
Cloud Pak for Network Automation
OpenManage Network Integration (OMNI)
Enterprise SONiC
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
IBM Business Automation Manager Open Editions
IBM VIOS
Nessus Network Monitor
Red Hat OpenShift Container Platform
Nessus Agent
IBM Qradar SIEM
NetWorker Management Console
Juniper Junos Space
libxmltok1 (Ubuntu package)
expat (Ubuntu package)
libexpat1 (Ubuntu package)
lib64expat1 (Ubuntu package)
libxmltok1t64 (Ubuntu package)
xmlrpc-c (Red Hat package)
xmlrpc-c-client++
xmlrpc-c-client
xmlrpc-c-devel
xmlrpc-c-doc
xmlrpc-c-c++
xmlrpc-c
xmlrpc-c-debuginfo
xmlrpc-c-debugsource
xmlrpc-c-help
libexpat1
libexpat1-debuginfo
expat
expat-debuginfo
libexpat-devel
expat-debuginfo-32bit
expat-debugsource
libexpat1-32bit
libexpat1-debuginfo-32bit
expat-devel
expat (Red Hat package)
expat-help
libexpat1-64bit
expat-64bit-debuginfo
libexpat-devel-64bit
expat-32bit-debuginfo
libexpat-devel-32bit
libexpat1-32bit-debuginfo
libexpat1-64bit-debuginfo
expat (Debian package)
expat-static
expat-doc
mingw-expat
python3.8
python3
python3.9
python3.10
mozjs52-debuginfo
libmozjs-52
mozjs52
libmozjs-52-debuginfo
mozjs52-debugsource
mozjs52-devel
libmozjs-60-debuginfo
mozjs60-devel
mozjs60-debuginfo
mozjs60
libmozjs-60
mozjs60-debugsource
mozjs78-debugsource
libmozjs-78-0-debuginfo
libmozjs-78-0
mozjs78-devel
mozjs78-debuginfo
mozjs78
dev-qt/qtwebengine
mozjs115
libmozjs-115-0
mozjs115-debuginfo
mozjs115-devel
libmozjs-115-0-debuginfo
mozjs115-debugsource
Red Hat OpenShift GitOps
IBM QRadar Network Packet Capture
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
iDRAC9

How to mitigate CVE-2024-45491

Install updates from vendor's website.

expat - update to 2.6.3
IBM Concert Software - update to 1.0.3
SmartFabric Storage Software - update to 1.4.3
Storage Defender - Resiliency Service - update to 2.0.11
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
Nessus Network Monitor - update to 6.5.0
LANTIME Operating System Firmware (LTOS) - update to 7.08.016
IBM OpenPages with Watson - update to 9.1.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Tenable Nessus - addressed in versions 10.7.6, 10.8.3
Nessus Agent - update to 10.7.3
IBM Security Verify Governance - update to 10.0.2.0.5
IBM Netezza Analytics for NPS - update to 11.2.30
Juniper Junos Space - update to 24.1R2
libxmltok1 (Ubuntu package) - update to Ubuntu Pro
expat (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.2.9-1ubuntu0.7, 2.4.7-1ubuntu0.4, 2.6.1-2ubuntu0.1
libexpat1 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.2.9-1ubuntu0.7, 2.4.7-1ubuntu0.4, 2.6.1-2ubuntu0.1
lib64expat1 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libxmltok1t64 (Ubuntu package) - update to Ubuntu Pro
Service Interconnect - addressed in versions 1, 1.4
Data Lakehouse - update to 1.3.0.0
Red Hat OpenShift GitOps - addressed in versions 1.12.6, 1.13.2
xmlrpc-c (Red Hat package) - update to 1.51.0-10.el8_10
xmlrpc-c-client++ - update to 1.51.0-10.0.1
xmlrpc-c-client - update to 1.51.0-10.0.1
xmlrpc-c-devel - update to 1.51.0-10.0.1
xmlrpc-c-doc - update to 1.51.0-10.0.1
xmlrpc-c-c++ - update to 1.51.0-10.0.1
xmlrpc-c - update to 1.51.0-10.0.1
xmlrpc-c - update to 1.51.08-3
xmlrpc-c-debuginfo - update to 1.51.08-3
xmlrpc-c-debugsource - update to 1.51.08-3
xmlrpc-c-devel - update to 1.51.08-3
xmlrpc-c-help - update to 1.51.08-3
xmlrpc-c - addressed in versions 1.60.04-1.fc42, 1.60.04-2.fc42
IBM MQ Operator - addressed in versions 2.0.28, 3.2.6, 3.3.0, 9.4.1.0-r1
libexpat1 - addressed in versions 2.1.0-21.37.1, 2.2.5-150000.3.30.1, 2.4.4-150400.3.22.1
libexpat1-debuginfo - addressed in versions 2.1.0-21.37.1, 2.2.5-150000.3.30.1, 2.4.4-150400.3.22.1
expat - addressed in versions 2.1.0-21.37.1, 2.4.4-150400.3.22.1
expat-debuginfo - addressed in versions 2.1.0-21.37.1, 2.2.5-150000.3.30.1, 2.4.4-150400.3.22.1
libexpat-devel - addressed in versions 2.1.0-21.37.1, 2.4.4-150400.3.22.1
expat-debuginfo-32bit - update to 2.1.0-21.37.1
expat-debugsource - addressed in versions 2.1.0-21.37.1, 2.2.5-150000.3.30.1, 2.4.4-150400.3.22.1
libexpat1-32bit - addressed in versions 2.1.0-21.37.1, 2.4.4-150400.3.22.1
libexpat1-debuginfo-32bit - update to 2.1.0-21.37.1
expat-devel - addressed in versions 2.2.5-13.0.1, 2.5.0-4
expat - addressed in versions 2.2.5-13.0.1, 2.5.0-4
expat (Red Hat package) - addressed in versions 2.2.5-15.el8_10, 2.5.0-2.el9_4.1
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.6, 2.6.3
expat-help - update to 2.4.1-13
expat-devel - update to 2.4.1-13
expat - update to 2.4.1-13
expat-debuginfo - update to 2.4.1-13
expat-debugsource - update to 2.4.1-13
libexpat1-64bit - update to 2.4.4-150400.3.22.1
expat-64bit-debuginfo - update to 2.4.4-150400.3.22.1
libexpat-devel-64bit - update to 2.4.4-150400.3.22.1
expat-32bit-debuginfo - update to 2.4.4-150400.3.22.1
libexpat-devel-32bit - update to 2.4.4-150400.3.22.1
libexpat1-32bit-debuginfo - update to 2.4.4-150400.3.22.1
libexpat1-64bit-debuginfo - update to 2.4.4-150400.3.22.1
OpenShift Service Mesh - addressed in versions 2.4.11, 2.5.5, 2.5.6, 2.6.2
expat (Debian package) - update to 2.5.0-1+deb12u1
expat-static - update to 2.5.0-4
expat-doc - update to 2.5.0-4
expat - update to 2.6.3
expat - addressed in versions 2.6.3-1.fc39, 2.6.3-1.fc40, 2.6.3-1.fc41
mingw-expat - addressed in versions 2.6.3-1.fc39, 2.6.3-1.fc40, 2.6.3-1.fc41
Cloud Pak for Network Automation - update to 2.7.7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.9.5, 2.11.3, 2.12.0
OpenManage Network Integration (OMNI) - update to 3.7
python3.8 - addressed in versions 3.8.20-1.fc39, 3.8.20-1.fc40, 3.8.20-1.fc41
python3 - update to 3.9.20
python3.9 - addressed in versions 3.9.20-1.fc39, 3.9.20-1.fc40, 3.9.20-1.fc41
python3.10 - addressed in versions 3.10.15-1.fc39, 3.10.15-1.fc40, 3.10.15-1.fc41
Enterprise SONiC - update to 4.4.1
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.5.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.13.12, 4.14.11, 4.16.3
Red Hat OpenShift Container Platform - addressed in versions 4.13.52, 4.14.38, 4.15.35, 4.16.15, 4.16.16, 4.17.0, 4.17.1, 4.17.5
App Connect Enterprise Certified Container - addressed in versions 5.0.22, 12.0.6, 12.6.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
OpenShift Logging - addressed in versions 5.6.24, 5.6.25, 5.8.13, 5.8.14, 5.9.7, 5.9.8, 6.0.1
Precision 7920 XL Rack - update to 7.00.00.181
iDRAC9 - addressed in versions 7.00.00.181, 7.20.30.50
Precision 7920 Rack - update to 7.00.00.181
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 11
IBM Business Automation Manager Open Editions - update to 8.0.6
NetWorker Management Console - update to 19.12.0.1
mozjs52-debuginfo - update to 52.6.0-150000.3.9.1
libmozjs-52 - update to 52.6.0-150000.3.9.1
mozjs52 - update to 52.6.0-150000.3.9.1
libmozjs-52-debuginfo - update to 52.6.0-150000.3.9.1
mozjs52-debugsource - update to 52.6.0-150000.3.9.1
mozjs52-devel - update to 52.6.0-150000.3.9.1
libmozjs-60-debuginfo - update to 60.9.0-150200.6.8.1
mozjs60-devel - update to 60.9.0-150200.6.8.1
mozjs60-debuginfo - update to 60.9.0-150200.6.8.1
mozjs60 - update to 60.9.0-150200.6.8.1
libmozjs-60 - update to 60.9.0-150200.6.8.1
mozjs60-debugsource - update to 60.9.0-150200.6.8.1
mozjs78-debugsource - update to 78.15.0-150400.3.6.2
libmozjs-78-0-debuginfo - update to 78.15.0-150400.3.6.2
libmozjs-78-0 - update to 78.15.0-150400.3.6.2
mozjs78-devel - update to 78.15.0-150400.3.6.2
mozjs78-debuginfo - update to 78.15.0-150400.3.6.2
mozjs78 - update to 78.15.0-150400.3.6.2
dev-qt/qtwebengine - update to 103.0.5060.53
mozjs115 - update to 115.4.0-150600.3.3.1
libmozjs-115-0 - update to 115.4.0-150600.3.3.1
mozjs115-debuginfo - update to 115.4.0-150600.3.3.1
mozjs115-devel - update to 115.4.0-150600.3.3.1
libmozjs-115-0-debuginfo - update to 115.4.0-150600.3.3.1
mozjs115-debugsource - update to 115.4.0-150600.3.3.1
IBM Observability with Instana - update to 284

External References

Related Security Bulletins