CVE-2024-50602

A

n issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:windows_host_utilities:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 7 (hide)

cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

History

15 Oct 2025, 17:54

Type Values Removed Values Added
CPE cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:windows_host_utilities:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
First Time Netapp h300s
Netapp solidfire \& Hci Storage Node
Netapp h410s Firmware
Netapp h410c Firmware
Netapp h700s
Netapp h700s Firmware
Netapp h500s
Netapp hci Compute Node
Netapp h410s
Netapp solidfire \& Hci Management Node
Netapp h300s Firmware
Netapp windows Host Utilities
Netapp active Iq Unified Manager
Libexpat Project libexpat
Debian
Netapp h500s Firmware
Netapp
Debian debian Linux
Libexpat Project
Netapp h410c
References () https://github.com/libexpat/libexpat/pull/915 - () https://github.com/libexpat/libexpat/pull/915 - Issue Tracking
References () https://lists.debian.org/debian-lts-announce/2025/04/msg00040.html - () https://lists.debian.org/debian-lts-announce/2025/04/msg00040.html - Mailing List, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20250404-0008/ - () https://security.netapp.com/advisory/ntap-20250404-0008/ - Third Party Advisory

30 Apr 2025, 20:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/04/msg00040.html -

04 Apr 2025, 23:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250404-0008/ -

30 Oct 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CWE CWE-754

28 Oct 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en libexpat antes de la versión 2.6.4. Se produce un bloqueo en la función XML_ResumeParser porque XML_StopParser puede detener o suspender un analizador no iniciado.

27 Oct 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-27 05:15

Updated : 2025-10-15 17:54


NVD link : CVE-2024-50602

Mitre link : CVE-2024-50602

CVE.ORG link : CVE-2024-50602


JSON object : View

CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions