This repository has been archived by the owner on Nov 6, 2020. It is now read-only.
CVE-2017-11742 (High) detected in expat-expat-2.2.1 #17
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2017-11742 - High Severity Vulnerability
Vulnerable Library - expatexpat-2.2.1
Fast XML parser library in C
Library home page: https://sourceforge.net/projects/expat/
Found in HEAD commit: 0b8ca0156130fe8d67f2fdd42af9d2f264587034
Library Source Files (17)
* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.
Vulnerability Details
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacking.
Publish Date: 2017-07-30
URL: CVE-2017-11742
CVSS 3 Score Details (7.8)
Base Score Metrics:
Suggested Fix
Type: Change files
Origin: libexpat/libexpat@d70eabf
Release Date: 2017-07-15
Fix Resolution: Replace or update the following files: Changes, xmlparse.c
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: