MGASA-2022-0031
Dashboard / Vulnerabilities / MGASA-2022-0031
MGASA-2022-0031
Summary: Updated expat packages fix security vulnerability
Details: In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). (CVE-2021-45960) In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. (CVE-2021-46143) addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. (CVE-2022-22822) build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. (CVE-2022-22823) defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. (CVE-2022-22824) lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. (CVE-2022-22825) nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. (CVE-2022-22826) storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. (CVE-2022-22827)
References: https://advisories.mageia.org/MGASA-2022-0031.html, https://bugs.mageia.org/show_bug.cgi?id=29902, https://blog.hartwork.org/posts/expat-2-4-3-released/, https://github.com/libexpat/libexpat/blob/R_2_4_3/expat/Changes
Affected packages
Package
Name: expat
Purl: pkg:rpm/mageia/expat?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
