[RHSA-2022:0951] expat security update

Severity Important
Affected Packages 10
CVEs 12

Expat is a C library for parsing XML documents.

Security Fix(es):

  • expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)

  • expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236)

  • expat: Integer overflow in storeRawNames() (CVE-2022-25315)

  • expat: Large number of prefixed XML attributes on a single tag can crash libexpat (CVE-2021-45960)

  • expat: Integer overflow in doProlog in xmlparse.c (CVE-2021-46143)

  • expat: Integer overflow in addBinding in xmlparse.c (CVE-2022-22822)

  • expat: Integer overflow in build_model in xmlparse.c (CVE-2022-22823)

  • expat: Integer overflow in defineAttribute in xmlparse.c (CVE-2022-22824)

  • expat: Integer overflow in lookup in xmlparse.c (CVE-2022-22825)

  • expat: Integer overflow in nextScaffoldPart in xmlparse.c (CVE-2022-22826)

  • expat: Integer overflow in storeAtts in xmlparse.c (CVE-2022-22827)

  • expat: Integer overflow in function XML_GetBuffer (CVE-2022-23852)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

ID
RHSA-2022:0951
Severity
important
URL
https://access.redhat.com/errata/RHSA-2022:0951
Published
2022-03-16T00:00:00
(2 years ago)
Modified
2022-03-16T00:00:00
(2 years ago)
Rights
Copyright 2022 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 2044451 https://bugzilla.redhat.com/2044451
Bugzilla 2044455 https://bugzilla.redhat.com/2044455
Bugzilla 2044457 https://bugzilla.redhat.com/2044457
Bugzilla 2044464 https://bugzilla.redhat.com/2044464
Bugzilla 2044467 https://bugzilla.redhat.com/2044467
Bugzilla 2044479 https://bugzilla.redhat.com/2044479
Bugzilla 2044484 https://bugzilla.redhat.com/2044484
Bugzilla 2044488 https://bugzilla.redhat.com/2044488
Bugzilla 2044613 https://bugzilla.redhat.com/2044613
Bugzilla 2056363 https://bugzilla.redhat.com/2056363
Bugzilla 2056366 https://bugzilla.redhat.com/2056366
Bugzilla 2056370 https://bugzilla.redhat.com/2056370
RHSA RHSA-2022:0951 https://access.redhat.com/errata/RHSA-2022:0951
CVE CVE-2021-45960 https://access.redhat.com/security/cve/CVE-2021-45960
CVE CVE-2021-46143 https://access.redhat.com/security/cve/CVE-2021-46143
CVE CVE-2022-22822 https://access.redhat.com/security/cve/CVE-2022-22822
CVE CVE-2022-22823 https://access.redhat.com/security/cve/CVE-2022-22823
CVE CVE-2022-22824 https://access.redhat.com/security/cve/CVE-2022-22824
CVE CVE-2022-22825 https://access.redhat.com/security/cve/CVE-2022-22825
CVE CVE-2022-22826 https://access.redhat.com/security/cve/CVE-2022-22826
CVE CVE-2022-22827 https://access.redhat.com/security/cve/CVE-2022-22827
CVE CVE-2022-23852 https://access.redhat.com/security/cve/CVE-2022-23852
CVE CVE-2022-25235 https://access.redhat.com/security/cve/CVE-2022-25235
CVE CVE-2022-25236 https://access.redhat.com/security/cve/CVE-2022-25236
CVE CVE-2022-25315 https://access.redhat.com/security/cve/CVE-2022-25315
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/expat?arch=x86_64&distro=redhat-8.5 redhat expat < 2.2.5-4.el8_5.3 redhat-8.5 x86_64
Affected pkg:rpm/redhat/expat?arch=s390x&distro=redhat-8.5 redhat expat < 2.2.5-4.el8_5.3 redhat-8.5 s390x
Affected pkg:rpm/redhat/expat?arch=ppc64le&distro=redhat-8.5 redhat expat < 2.2.5-4.el8_5.3 redhat-8.5 ppc64le
Affected pkg:rpm/redhat/expat?arch=i686&distro=redhat-8.5 redhat expat < 2.2.5-4.el8_5.3 redhat-8.5 i686
Affected pkg:rpm/redhat/expat?arch=aarch64&distro=redhat-8.5 redhat expat < 2.2.5-4.el8_5.3 redhat-8.5 aarch64
Affected pkg:rpm/redhat/expat-devel?arch=x86_64&distro=redhat-8.5 redhat expat-devel < 2.2.5-4.el8_5.3 redhat-8.5 x86_64
Affected pkg:rpm/redhat/expat-devel?arch=s390x&distro=redhat-8.5 redhat expat-devel < 2.2.5-4.el8_5.3 redhat-8.5 s390x
Affected pkg:rpm/redhat/expat-devel?arch=ppc64le&distro=redhat-8.5 redhat expat-devel < 2.2.5-4.el8_5.3 redhat-8.5 ppc64le
Affected pkg:rpm/redhat/expat-devel?arch=i686&distro=redhat-8.5 redhat expat-devel < 2.2.5-4.el8_5.3 redhat-8.5 i686
Affected pkg:rpm/redhat/expat-devel?arch=aarch64&distro=redhat-8.5 redhat expat-devel < 2.2.5-4.el8_5.3 redhat-8.5 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...