CVE-2012-1148

Modified
Published: 03 Jul 2012, 19:00
Last modified:06 Aug 2024, 18:45

Vulnerability Summary

Overall Risk (default)
low
20/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
0.97% LOW
1% probability -0.32%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jul 2012, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 18:45
Last Modified
Vulnerability information updated

Description

Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.97% Percentile: 77%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • applemac_os_x

    ≤ 10.11.1

  • libexpat_projectlibexpat

    ≤ 2.0.1 | 1.95.1 | 1.95.2 | 1.95.4 | 1.95.5 | 1.95.6 | 1.95.7 | 1.95.8 | 2.0.0

References (18)