expat 2.1.0 has open CVE-2013-0340
Is there actually anything to be done about this CVE? From what I can tell the general consensus was to assign CVEs for applications that use it that are vulnerable and do nothing specifically about this CVE itself: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0340 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0340 http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-0340.html
Marking as NEEDINFO as per above comment.
The CVSS score on this is medium. this issue is on the App developer not expact 2.1.0 Applications linked with expat can mitigate this issue, by calling the XML_SetEntityDeclHandler() function with the name of an alternative function that can handle entities more safely. Since API levels mitigations are in place, closing this as wontfix.
Verified as per above comments.