#VU68718 Use-after-free in expat - CVE-2022-43680
Published: October 25, 2022 / Updated: December 29, 2023
expat
libexpat.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate. A remote attacker can trigger a use-after-free error and perform a denial of service (DoS) attack.