CVE-2023-52425: High severity Libexpat Project Libexpat vulnerability
libexpat is vulnerable to a denial of service, caused by improper system resource allocation. By sending a specially crafted request using an overly large token, a remote attacker could exploit this vulnerability to cause a denial of service.
Other sources
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
— Ubuntu
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52425?
CVE-2023-52425 has a severity of medium due to its potential to cause denial of service through improper system resource allocation.
How do I fix CVE-2023-52425?
To fix CVE-2023-52425, you should update the libexpat package to versions 2.2.6-2+deb10u7, 2.6.2-1 in Debian or to 2.4.7-1ubuntu0.3, 2.5.0-2ubuntu0.1, or 2.6.0-1 in Ubuntu.
Which versions of expat are affected by CVE-2023-52425?
Versions of expat up to and including 2.5.0 are affected by CVE-2023-52425.
Can CVE-2023-52425 be exploited remotely?
Yes, CVE-2023-52425 can be exploited remotely by sending specially crafted requests with overly large tokens.
What is the impact of CVE-2023-52425 on affected systems?
The impact of CVE-2023-52425 on affected systems is a denial of service, which can disrupt service availability.