[FEDORA-2022-04f206996b] Fedora 34: mingw-expat

Severity Critical
Affected Packages 1
CVEs 5

Update to expat-2.4.6, see
https://github.com/libexpat/libexpat/blob/R_2_4_6/expat/Changes for details.

Package Affected Version
pkg:rpm/fedora/mingw-expat?distro=fedora-34 < 2.4.6.1.fc34
Source # ID Name URL
Bugzilla 2056352 Bug #2056352 - CVE-2022-25313 mingw-expat: expat: stack exhaustion in doctype parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2056352
Bugzilla 2056372 Bug #2056372 - CVE-2022-25236 mingw-expat: expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2056372
Bugzilla 2056365 Bug #2056365 - CVE-2022-25315 mingw-expat: expat: integer overflow in storeRawNames() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2056365
Bugzilla 2056368 Bug #2056368 - CVE-2022-25235 mingw-expat: expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2056368
Bugzilla 2056355 Bug #2056355 - CVE-2022-25314 mingw-expat: expat: integer overflow in copyString() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2056355
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/mingw-expat?distro=fedora-34 fedora mingw-expat < 2.4.6.1.fc34 fedora-34
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...