漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Expat Denial of Service via storeAtts() Quadratic Complexity
Vulnerability Description
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
算法复杂性
Vulnerability Title
libexpat 资源管理错误漏洞
Vulnerability Description
libexpat是libexpat团队开源的一款轻量级的XML解析库。 libexpat 2.8.3及之前版本存在资源管理错误漏洞,该漏洞源于xmlparse.c中的storeAtts()函数存在二次算法复杂度问题,处理非规范化属性时触发O(N^2)线性扫描,远程未认证攻击者可能利用少量XML文档导致CPU过度消耗,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A