libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c
Just in case you ever derived your code from it...
via Fefes Blog
Security warning: use-after-free issue in expat
Forum rules
Please keep everything here strictly on-topic.
This board is meant for Pale Moon source code development related subjects only like code snippets, patches, specific bugs, git, the repositories, etc.
This is not for tech support! Please do not post tech support questions in the "Development" board!
Please make sure not to use this board for support questions. Please post issues with specific websites, extensions, etc. in the relevant boards for those topics.
Please keep things on-topic as this forum will be used for reference for Pale Moon development. Expect topics that aren't relevant as such to be moved or deleted.
Please keep everything here strictly on-topic.
This board is meant for Pale Moon source code development related subjects only like code snippets, patches, specific bugs, git, the repositories, etc.
This is not for tech support! Please do not post tech support questions in the "Development" board!
Please make sure not to use this board for support questions. Please post issues with specific websites, extensions, etc. in the relevant boards for those topics.
Please keep things on-topic as this forum will be used for reference for Pale Moon development. Expect topics that aren't relevant as such to be moved or deleted.
Security warning: use-after-free issue in expat
Fun and success!
- jobbautista9
- Contributing developer
- Posts: 627
- Joined: 2020-11-03, 06:47
- Location: Philippines
- Contact:
Re: Security warning: use-after-free issue in expat
Mozilla is tracking this in bug #1791598, fyi.

Mima world
XUL add-ons developer. You can find a list of add-ons I manage at http://rw.rs/~job/software.html.
My PGP public key (My copy on rw.rs)
Mima avatar by 累々るい of pixiv: https://www.pixiv.net/en/artworks/103784502
Re: Security warning: use-after-free issue in expat
Filed Issue #2010 (UXP)
"The best revenge is to not be like the person who wronged you." -- Marcus Aurelius
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb