CVE-2012-1148
EPSS 0.97%
Description
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
How to fix CVE-2012-1148
To remediate CVE-2012-1148, upgrade the affected package to a fixed version below.
- Debian/expat—upgrade to 2.1.0~beta3-1 or later
- Debian/libxmltok—no fix listed
- Debian/xmlrpc-c—upgrade to 1.16.33-3.2 or later
Is CVE-2012-1148 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2.1.0~beta3-1
- from 0
- from 0, < 1.16.33-3.2