[FEDORA-2022-04f206996b] Fedora 34: mingw-expat
Severity
Critical
Affected Packages
1
CVEs
5
Update to expat-2.4.6, see
https://github.com/libexpat/libexpat/blob/R_2_4_6/expat/Changes for details.
Package | Affected Version |
---|---|
pkg:rpm/fedora/mingw-expat?distro=fedora-34 | < 2.4.6.1.fc34 |
- ID
- FEDORA-2022-04f206996b
- Severity
- critical
- Severity from
- CVE-2022-25315
- URL
- https://bodhi.fedoraproject.org/updates/FEDORA-2022-04f206996b
- Published
-
2022-03-01T18:37:17
(2 years ago) - Modified
-
2022-03-01T18:37:17
(2 years ago) - Rights
- Copyright 2022 Red Hat, Inc.
- Other Advisories
-
- ALAS-2022-1570
- ALAS-2022-1573
- ALAS-2022-1585
- ALAS2-2022-1759
- ALAS2-2022-1764
- ALAS2-2022-1779
- ALAS2-2022-1795
- ALAS2-2023-2280
- ALPINE:CVE-2022-25235
- ALPINE:CVE-2022-25236
- ALPINE:CVE-2022-25313
- ALPINE:CVE-2022-25314
- ALPINE:CVE-2022-25315
- ALSA-2022:0818
- ALSA-2022:0845
- ALSA-2022:0951
- ALSA-2022:1643
- ALSA-2022:5244
- ALSA-2022:5314
- ALSA-2022:7811
- ASB-A-221384482
- DSA-5085-1
- ELSA-2022-0818
- ELSA-2022-0824
- ELSA-2022-0845
- ELSA-2022-0850
- ELSA-2022-0951
- ELSA-2022-1069
- ELSA-2022-1643
- ELSA-2022-5244
- ELSA-2022-5314
- ELSA-2022-9359
- FEDORA-2022-01f0553b59
- FEDORA-2022-3d9d67f558
- FEDORA-2022-f202d1a045
- FEDORA-2023-97a977a96a
- FEDORA-2023-99ba1917da
- GLSA-202209-24
- MS:CVE-2022-25235
- MS:CVE-2022-25236
- MS:CVE-2022-25313
- MS:CVE-2022-25314
- MS:CVE-2022-25315
- openSUSE-SU-2022:0713-1
- openSUSE-SU-2022:0844-1
- RHSA-2022:0818
- RHSA-2022:0824
- RHSA-2022:0845
- RHSA-2022:0850
- RHSA-2022:0951
- RHSA-2022:1069
- RHSA-2022:1643
- RHSA-2022:5244
- RHSA-2022:5314
- RHSA-2022:7811
- SSA:2022-050-01
- SUSE-SU-2022:0698-1
- SUSE-SU-2022:0713-1
- SUSE-SU-2022:0842-1
- SUSE-SU-2022:0844-1
- SUSE-SU-2022:0844-2
- SUSE-SU-2022:2294-1
- SUSE-SU-2024:0782-1
- SUSE-SU-2024:0782-2
- SUSE-SU-2024:0784-1
- USN-5288-1
- USN-5320-1
- USN-5455-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 2056352 | Bug #2056352 - CVE-2022-25313 mingw-expat: expat: stack exhaustion in doctype parsing [fedora-all] | https://bugzilla.redhat.com/show_bug.cgi?id=2056352 |
Bugzilla | 2056372 | Bug #2056372 - CVE-2022-25236 mingw-expat: expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution [fedora-all] | https://bugzilla.redhat.com/show_bug.cgi?id=2056372 |
Bugzilla | 2056365 | Bug #2056365 - CVE-2022-25315 mingw-expat: expat: integer overflow in storeRawNames() [fedora-all] | https://bugzilla.redhat.com/show_bug.cgi?id=2056365 |
Bugzilla | 2056368 | Bug #2056368 - CVE-2022-25235 mingw-expat: expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution [fedora-all] | https://bugzilla.redhat.com/show_bug.cgi?id=2056368 |
Bugzilla | 2056355 | Bug #2056355 - CVE-2022-25314 mingw-expat: expat: integer overflow in copyString() [fedora-all] | https://bugzilla.redhat.com/show_bug.cgi?id=2056355 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/fedora/mingw-expat?distro=fedora-34 | fedora | mingw-expat | < 2.4.6.1.fc34 | fedora-34 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |