Vulnerability CVE-2022-23852: Information
Description
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
expat | sisyphus | 2.4.4-alt1 | 2.5.0-alt1 | ALT-PU-2022-1208-1 | 294677 | Fixed |
expat | sisyphus_e2k | 2.4.4-alt1 | 2.5.0-alt1 | ALT-PU-2022-3934-1 | - | Fixed |
expat | sisyphus_riscv64 | 2.4.4-alt1 | 2.5.0-alt1 | ALT-PU-2022-3982-1 | - | Fixed |
expat | p10 | 2.5.0-alt1 | 2.5.0-alt1 | ALT-PU-2023-4144-2 | 324220 | Fixed |
expat | p10_e2k | 2.5.0-alt1 | 2.5.0-alt1 | ALT-PU-2023-5082-1 | - | Fixed |
expat | c10f1 | 2.5.0-alt1 | 2.5.0-alt1 | ALT-PU-2023-4120-1 | 324221 | Fixed |
expat | c9f2 | 2.5.0-alt1 | 2.5.0-alt1 | ALT-PU-2023-4107-2 | 324219 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://github.com/libexpat/libexpat/pull/550 |
|
https://www.tenable.com/security/tns-2022-05 |
|
DSA-5073 |
|
https://security.netapp.com/advisory/ntap-20220217-0001/ |
|
[debian-lts-announce] 20220307 [SECURITY] [DLA 2935-1] expat security update |
|
https://www.oracle.com/security-alerts/cpuapr2022.html |
|
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf |
|
GLSA-202209-24 |
|