Description
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Remediation
References
Related Vulnerabilities
Apache Tomcat Improper Access Control Vulnerability (CVE-2016-5388)
MySQL CVE-2018-3066 Vulnerability (CVE-2018-3066)
WordPress Plugin Genesis Columns Advanced Cross-Site Scripting (2.0.3)
WebLogic CVE-2020-2966 Vulnerability (CVE-2020-2966)
Squid Integer Overflow or Wraparound Vulnerability (CVE-2020-11945)