在 libexpat 2.8.2 和 2.8.3 版本(未更新至 2.8.4)中,对 返回值的错误解读会导致熵值不足,从而易受哈希泛洪攻击的影响,攻击者可通过构造恶意 XML 内容导致拒绝服务(DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| libexpat project | libexpat | 2.8.2< 2.8.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| libexpat project | libexpat | 2.8.2 ~ 2.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet