CVE-2024-45490: Input Validation
Accounts. A logic issue was addressed with improved file handling.
Other sources
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XMLParseBuffer.
— NVD
APFS. This issue was addressed through improved state management.
— Apple
Apple Account. The issue was addressed with improved handling of protocols.
— Apple
Apple Software Restore. The issue was addressed with improved checks.
— Apple
AppleGraphicsControl. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-54541
- CVE-2024-54513
- CVE-2024-54486
- CVE-2024-54478
- CVE-2024-54499
- CVE-2024-54500
- CVE-2024-44245
- CVE-2024-54494
- CVE-2024-45490
- CVE-2024-54525
- CVE-2024-54530
- CVE-2024-54492
- CVE-2024-54497
- CVE-2024-54501
- CVE-2024-45306
- CVE-2024-54479
- CVE-2024-54502
- CVE-2024-54508
- CVE-2024-54505
- CVE-2024-54534
- CVE-2024-54543
- CVE-2024-40864
- CVE-2024-54526
- CVE-2024-54527
- CVE-2024-54512
- CVE-2024-54517
- CVE-2024-54518
- CVE-2024-54522
- CVE-2024-54523
- CVE-2024-54468
- CVE-2024-54510
- CVE-2024-54514
- CVE-2024-44225
- CVE-2024-54542
- CVE-2024-54488
- CVE-2024-54503
- CVE-2024-54550
- CVE-2024-54507
- CVE-2024-44276
- CVE-2024-44246
- CVE-2024-54485
- CVE-2024-44201
- CVE-2025-24091
- CVE-2024-54477
- CVE-2024-44220
- CVE-2024-54509
- CVE-2024-54529
- CVE-2024-44300
- CVE-2024-54466
- CVE-2024-54489
- CVE-2024-54547
- CVE-2024-54519
- CVE-2024-54474
- CVE-2024-54476
- CVE-2024-54537
- CVE-2024-44248
- CVE-2024-54557
- CVE-2024-54516
- CVE-2024-54528
- CVE-2024-54498
- CVE-2024-44291
- CVE-2024-44224
- CVE-2024-54495
- CVE-2024-54520
- CVE-2024-54475
- CVE-2024-54539
- CVE-2024-54490
- CVE-2024-54568
- CVE-2024-44271
- CVE-2024-54506
- CVE-2024-54531
- CVE-2024-54465
- CVE-2024-54491
- CVE-2024-54484
- CVE-2024-54536
- CVE-2024-54504
- CVE-2016-1246
- CVE-2023-31484
- CVE-2023-31486
- CVE-2023-47100
- CVE-2023-32395
- CVE-2024-54559
- CVE-2024-54515
- CVE-2024-54524
- CVE-2024-54493
- CVE-2024-54533
- CVE-2024-44243
- CVE-2024-54549
- CVE-2024-54565
Frequently Asked Questions
What is the severity of CVE-2024-45490?
The severity of CVE-2024-45490 has not been explicitly classified, but it involves a logic issue in file handling that could potentially be exploited.
How do I fix CVE-2024-45490?
To fix CVE-2024-45490, update the affected software to the designated versions such as libexpat 2.6.4 or later.
Which versions of libexpat are affected by CVE-2024-45490?
Versions of libexpat prior to 2.6.3 are affected by CVE-2024-45490.
What products are impacted by CVE-2024-45490?
CVE-2024-45490 impacts several products including Debian's expat package, Apple macOS versions, and IBM's Concert Software.
Are there any known exploits for CVE-2024-45490?
As of now, there are no publicly known exploits specifically targeting CVE-2024-45490.