Skip to content
This repository has been archived by the owner on Apr 19, 2019. It is now read-only.

expat vulnerability CVE-2016-4472 #195

Open
ipuustin opened this issue Oct 6, 2016 · 1 comment
Open

expat vulnerability CVE-2016-4472 #195

ipuustin opened this issue Oct 6, 2016 · 1 comment

Comments

@ipuustin
Copy link
Contributor

ipuustin commented Oct 6, 2016

Base CVSS severity 8.1 (high). Ostro OS severity not yet analyzed.

https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4472

@ipuustin
Copy link
Contributor Author

ipuustin commented Oct 7, 2016

It seems that this is issue is a false alarm -- the fix is already in expat 2.2.0 event though the CVE database indicates expat 2.2.0 to be vulnerable. See https://sourceforge.net/p/expat/code_git/ci/master/tree/expat/Changes for the list of CVE fixes included in 2.2.0 release.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant