ID

VAR-202408-2685


CVE

CVE-2024-45491


TITLE

libexpat project  of  libexpat  Integer overflow vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-007192

DESCRIPTION

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX). libexpat project of libexpat Exists in an integer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces. SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs). Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server. ========================================================================== Ubuntu Security Notice USN-7001-2 September 17, 2024 libxmltok vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in libxmltok. Software Description: - libxmltok: XML Parser Toolkit, developer libraries Details: USN-7001-1 fixed vulnerabilities in xmltol library. This update provides the corresponding updates for Ubuntu 24.04 LTS. Original advisory details: Shang-Hung Wan discovered that Expat, contained within the xmltok library, did not properly handle certain function calls when a negative input length was provided. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45490) Shang-Hung Wan discovered that Expat, contained within the xmltok library, did not properly handle the potential for an integer overflow on 32-bit platforms. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45491) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libxmltok1t64 1.2-4.1ubuntu2.24.0.4.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5770-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 17, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : expat CVE ID : CVE-2024-45490 CVE-2024-45491 CVE-2024-45492 Shang-Hung Wan discovered multiple vulnerabilities in the Expat XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in version 2.5.0-1+deb12u1. We recommend that you upgrade your expat packages. For the detailed security status of expat please refer to its security tracker page at: https://security-tracker.debian.org/tracker/expat Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmbp6EIACgkQEMKTtsN8 Tjb+0hAAsAHl9didzh1S8vHaLH8P8I1XT0302RGP1N6r4BKvjEozuTKml28F3NEK 9IplBZXH8GM6tnF1/gRJf5Dp4YsL7H+nYUjbkZEdLM2TztRoy4wnITxUwqQ7q1ly /bWMuyaoUn9jZu6SA+yEL68DtbXpFbs8IAOE3kqPsbcWvJ7O7LU3Ajjw5aWYwxV0 kdVyI67rBkfWAdyFRjlkxF62+ieR9sjpKNDKK1nmO+I8eEF5E/WOXsfPlzcKwax2 mMhisTscEIvaBSKCaQICCojYbvju8KW8B+NsJMsyRbPoimTyzE2n4VBk0ZNHjv+w sIddwdgzXpWHHRbVtl6zjiZvzxUtphp6tHstxoW8YZQKkQiwqqlpONqXKWG1yR0o pltUr7JjTylDo41M21yK/WizdxFkdrUJi4drKTONekvbhUEaTLaoR/ywYi0Za7T0 sUguAJk25id2px3LdTvMhQywTNmL103LkFfq1WIXL9x+yzYdKos8P3qu9DIaIqms R4dy2xMhiJwVyQXi74Tte9h5n6FXET1Z8MoyxFOVI6SQ5FBXJMmL48r6Uwhb09tH ZL2VNUequSC2L4uGozFFaHvr3M606srokRbo18XvNTNUvApJjAFt/WTnOjKUDuJM 08PjLw6brD/XBR6p/NKX8vMQmmXClyKwB97SG1MYu/MfdJK/7wQ= =bEe8 -----END PGP SIGNATURE----- . The following advisory data is extracted from: https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8859.json Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment. - Packet Storm Staff ==================================================================== Red Hat Security Advisory Synopsis: Moderate: xmlrpc-c security update Advisory ID: RHSA-2024:8859-03 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2024:8859 Issue date: 2024-11-05 Revision: 03 CVE Names: CVE-2024-45491 ==================================================================== Summary: An update for xmlrpc-c is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description: XML-RPC is a remote procedure call (RPC) protocol that uses XML to encode its calls and HTTP as a transport mechanism. The xmlrpc-c packages provide a network protocol to allow a client program to make a simple RPC (remote procedure call) over the Internet. It converts an RPC into an XML document, sends it to a remote server using HTTP, and gets back the response in XML. Security Fix(es): * libexpat: Integer Overflow or Wraparound (CVE-2024-45491) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution: https://access.redhat.com/articles/11258 CVEs: CVE-2024-45491 References: https://access.redhat.com/security/updates/classification/#moderate https://bugzilla.redhat.com/show_bug.cgi?id=2308616

Trust: 2.52

sources: NVD: CVE-2024-45491 // JVNDB: JVNDB-2024-007192 // CNVD: CNVD-2025-19346 // PACKETSTORM: 181487 // PACKETSTORM: 181587 // PACKETSTORM: 181605 // PACKETSTORM: 182499

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-19346

AFFECTED PRODUCTS

vendor:libexpatmodel:libexpatscope:ltversion:2.6.3

Trust: 1.0

vendor:libexpatmodel:libexpatscope: - version: -

Trust: 0.8

vendor:libexpatmodel:libexpatscope:eqversion:2.6.3

Trust: 0.8

vendor:libexpatmodel:libexpatscope:eqversion: -

Trust: 0.8

vendor:siemensmodel:ruggedcom rst2428pscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xc-300/xr-300/xc-400/xr-500wg/xr-500 familyscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xcm-/xrm-/xch-/xrh-300 familyscope:ltversion:v3.1

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-007192 // NVD: CVE-2024-45491

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-45491
value: CRITICAL

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-45491
value: HIGH

Trust: 1.0

NVD: CVE-2024-45491
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2025-19346
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-19346
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-45491
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-45491
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 3.4
version: 3.1

Trust: 1.0

NVD: CVE-2024-45491
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-007192 // NVD: CVE-2024-45491 // NVD: CVE-2024-45491

PROBLEMTYPE DATA

problemtype:CWE-190

Trust: 1.0

problemtype:Integer overflow or wraparound (CWE-190) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-007192 // NVD: CVE-2024-45491

TYPE

arbitrary

Trust: 0.2

sources: PACKETSTORM: 181587 // PACKETSTORM: 181605

PATCH

title:Patch for Multiple vulnerabilities in Siemens SINEC OS third-party componentsurl:https://www.cnvd.org.cn/patchInfo/show/723071

Trust: 0.6

sources: CNVD: CNVD-2025-19346

EXTERNAL IDS

db:NVDid:CVE-2024-45491

Trust: 3.0

db:SIEMENSid:SSA-613116

Trust: 1.6

db:SIEMENSid:SSA-082556

Trust: 1.0

db:JVNid:JVNVU93117073

Trust: 0.8

db:JVNid:JVNVU91160009

Trust: 0.8

db:JVNid:JVNVU96443907

Trust: 0.8

db:ICS CERTid:ICSA-25-162-05

Trust: 0.8

db:ICS CERTid:ICSA-25-259-02

Trust: 0.8

db:ICS CERTid:ICSA-24-317-01

Trust: 0.8

db:JVNDBid:JVNDB-2024-007192

Trust: 0.8

db:CNVDid:CNVD-2025-19346

Trust: 0.6

db:PACKETSTORMid:181487

Trust: 0.1

db:PACKETSTORMid:181587

Trust: 0.1

db:PACKETSTORMid:181605

Trust: 0.1

db:PACKETSTORMid:182499

Trust: 0.1

sources: CNVD: CNVD-2025-19346 // PACKETSTORM: 181487 // PACKETSTORM: 181587 // PACKETSTORM: 181605 // PACKETSTORM: 182499 // JVNDB: JVNDB-2024-007192 // NVD: CVE-2024-45491

REFERENCES

url:https://github.com/libexpat/libexpat/issues/888

Trust: 1.8

url:https://github.com/libexpat/libexpat/pull/891

Trust: 1.8

url:https://cert-portal.siemens.com/productcert/html/ssa-613116.html

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2024-45491

Trust: 1.2

url:https://cert-portal.siemens.com/productcert/html/ssa-082556.html

Trust: 1.0

url:https://lists.debian.org/debian-lts-announce/2024/09/msg00036.html

Trust: 1.0

url:https://security.netapp.com/advisory/ntap-20241018-0003/

Trust: 1.0

url:https://jvn.jp/vu/jvnvu91160009/

Trust: 0.8

url:https://jvn.jp/vu/jvnvu96443907/

Trust: 0.8

url:https://jvn.jp/vu/jvnvu93117073/index.html

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-24-317-01

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-259-02

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-45490

Trust: 0.3

url:https://ubuntu.com/security/notices/usn-7001-1

Trust: 0.2

url:https://ubuntu.com/security/notices/usn-7001-2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2024-45492

Trust: 0.1

url:https://www.debian.org/security/faq

Trust: 0.1

url:https://security-tracker.debian.org/tracker/expat

Trust: 0.1

url:https://www.debian.org/security/

Trust: 0.1

url:https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8859.json

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2024:8859

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=2308616

Trust: 0.1

url:https://access.redhat.com/articles/11258

Trust: 0.1

sources: CNVD: CNVD-2025-19346 // PACKETSTORM: 181487 // PACKETSTORM: 181587 // PACKETSTORM: 181605 // PACKETSTORM: 182499 // JVNDB: JVNDB-2024-007192 // NVD: CVE-2024-45491

CREDITS

Ubuntu

Trust: 0.2

sources: PACKETSTORM: 181487 // PACKETSTORM: 181587

SOURCES

db:CNVDid:CNVD-2025-19346
db:PACKETSTORMid:181487
db:PACKETSTORMid:181587
db:PACKETSTORMid:181605
db:PACKETSTORMid:182499
db:JVNDBid:JVNDB-2024-007192
db:NVDid:CVE-2024-45491

LAST UPDATE DATE

2026-06-19T20:23:36.156000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-22T00:00:00
db:JVNDBid:JVNDB-2024-007192date:2025-09-19T07:36:00
db:NVDid:CVE-2024-45491date:2026-05-12T12:17:10.750

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-12T00:00:00
db:PACKETSTORMid:181487date:2024-09-12T14:53:00
db:PACKETSTORMid:181587date:2024-09-17T15:37:02
db:PACKETSTORMid:181605date:2024-09-18T14:29:17
db:PACKETSTORMid:182499date:2024-11-05T15:20:19
db:JVNDBid:JVNDB-2024-007192date:2024-09-05T00:00:00
db:NVDid:CVE-2024-45491date:2024-08-30T03:15:03.850