ALSA-2022:0951
Dashboard / Vulnerabilities / ALSA-2022:0951
ALSA-2022:0951
Summary: Important: expat security update
Details: Expat is a C library for parsing XML documents. Security Fix(es): * expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235) * expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236) * expat: Integer overflow in storeRawNames() (CVE-2022-25315) * expat: Large number of prefixed XML attributes on a single tag can crash libexpat (CVE-2021-45960) * expat: Integer overflow in doProlog in xmlparse.c (CVE-2021-46143) * expat: Integer overflow in addBinding in xmlparse.c (CVE-2022-22822) * expat: Integer overflow in build_model in xmlparse.c (CVE-2022-22823) * expat: Integer overflow in defineAttribute in xmlparse.c (CVE-2022-22824) * expat: Integer overflow in lookup in xmlparse.c (CVE-2022-22825) * expat: Integer overflow in nextScaffoldPart in xmlparse.c (CVE-2022-22826) * expat: Integer overflow in storeAtts in xmlparse.c (CVE-2022-22827) * expat: Integer overflow in function XML_GetBuffer (CVE-2022-23852) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2022:0951, https://access.redhat.com/security/cve/CVE-2021-45960, https://access.redhat.com/security/cve/CVE-2021-46143, https://access.redhat.com/security/cve/CVE-2022-22822, https://access.redhat.com/security/cve/CVE-2022-22823, https://access.redhat.com/security/cve/CVE-2022-22824, https://access.redhat.com/security/cve/CVE-2022-22825, https://access.redhat.com/security/cve/CVE-2022-22826, https://access.redhat.com/security/cve/CVE-2022-22827, https://access.redhat.com/security/cve/CVE-2022-23852, https://access.redhat.com/security/cve/CVE-2022-25235, https://access.redhat.com/security/cve/CVE-2022-25236, https://access.redhat.com/security/cve/CVE-2022-25315, https://bugzilla.redhat.com/2044451, https://bugzilla.redhat.com/2044455, https://bugzilla.redhat.com/2044457, https://bugzilla.redhat.com/2044464, https://bugzilla.redhat.com/2044467, https://bugzilla.redhat.com/2044479, https://bugzilla.redhat.com/2044484, https://bugzilla.redhat.com/2044488, https://bugzilla.redhat.com/2044613, https://bugzilla.redhat.com/2056363, https://bugzilla.redhat.com/2056366, https://bugzilla.redhat.com/2056370, https://errata.almalinux.org/8/ALSA-2022-0951.html
Affected packages
Package
Name: expat
Purl: pkg:rpm/almalinux/expat
Affected ranges
Type: ECOSYSTEM
Events:
