CVE-2024-45492
CVE Details
Last Update
9/5/24
NIST CVE Summary
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Our Official Summary
This CVE identifies an integer overflow vulnerability found in libexpat versions prior to 2.6.3, which can lead to an integer overflow in the nextScaffoldPart function on 32-bit platforms. This vulnerability can be exploited over a network without user interaction and has very low attack complexity. Not all of the images affected use the specific function affected. Exploiting this vulnerable library will require a user to compromise the containers and gain privileged access. Fix available in libexpat versions > 2.6.3. Investigating upgrading this library within the affected images.
CVE Severity
Status
Ongoing
Affected Products & Versions
- Palette VerteX 4.4.14
Revision History
- 1.0 09/05/2024 Initial Publication
- 2.0 09/05/2024 Added Palette VerteX 4.4.14 to Affected Products