Vulnerability CVE-2022-22825: Information
Description
lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
expat | sisyphus | 2.4.3-alt1 | 2.5.0-alt1 | ALT-PU-2022-1072-1 | 293693 | Fixed |
expat | sisyphus_e2k | 2.4.3-alt1 | 2.5.0-alt1 | ALT-PU-2022-3713-1 | - | Fixed |
expat | sisyphus_mipsel | 2.4.3-alt1 | 2.5.0-alt1 | ALT-PU-2022-3682-1 | - | Fixed |
expat | sisyphus_riscv64 | 2.4.3-alt1 | 2.5.0-alt1 | ALT-PU-2022-3686-1 | - | Fixed |
expat | p10 | 2.4.3-alt1 | 2.5.0-alt1 | ALT-PU-2022-1130-1 | 293695 | Fixed |
expat | p10_e2k | 2.4.3-alt1 | 2.5.0-alt1 | ALT-PU-2022-3808-1 | - | Fixed |
expat | p9 | 2.4.3-alt1 | 2.4.3-alt1 | ALT-PU-2022-1176-1 | 293696 | Fixed |
expat | p9_e2k | 2.4.3-alt1 | 2.4.3-alt1 | ALT-PU-2022-4725-1 | - | Fixed |
expat | p9_mipsel | 2.4.3-alt1 | 2.4.3-alt1 | ALT-PU-2022-4000-1 | - | Fixed |
expat | c10f1 | 2.4.3-alt1 | 2.5.0-alt1 | ALT-PU-2022-1130-1 | 293695 | Fixed |
expat | c9f2 | 2.5.0-alt1 | 2.5.0-alt1 | ALT-PU-2023-4107-2 | 324219 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://github.com/libexpat/libexpat/pull/539 |
|
[oss-security] 20220117 Expat 2.4.3 released, includes 8 security fixes |
|
https://www.tenable.com/security/tns-2022-05 |
|
DSA-5073 |
|
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf |
|
GLSA-202209-24 |
|