USN-5455-1
Dashboard / Vulnerabilities / USN-5455-1
USN-5455-1
Summary: libxmltok vulnerabilities
Details: Tim Boddy, Gustavo Grieco and others discovered that Expat, that is integrated in xmltok library, incorrectly handled certain files. An attacker could possibly use these issues to cause a denial of service, or possibly execute arbitrary code. These issues were only addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283, CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827) It was discovered that Expat, that is integrated in xmltok library, incorrectly handled encoding validation of certain files. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-25235) It was discovered that Expat, that is integrated in xmltok library, incorrectly handled namespace URIs of certain files. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-25236)
References: https://ubuntu.com/security/notices/USN-5455-1, https://ubuntu.com/security/CVE-2012-1148, https://ubuntu.com/security/CVE-2015-1283, https://ubuntu.com/security/CVE-2016-0718, https://ubuntu.com/security/CVE-2016-4472, https://ubuntu.com/security/CVE-2018-20843, https://ubuntu.com/security/CVE-2019-15903, https://ubuntu.com/security/CVE-2021-46143, https://ubuntu.com/security/CVE-2022-22822, https://ubuntu.com/security/CVE-2022-22823, https://ubuntu.com/security/CVE-2022-22824, https://ubuntu.com/security/CVE-2022-22825, https://ubuntu.com/security/CVE-2022-22826, https://ubuntu.com/security/CVE-2022-22827, https://ubuntu.com/security/CVE-2022-25235, https://ubuntu.com/security/CVE-2022-25236
Affected packages
Package
Name: libxmltok
Purl: pkg:deb/ubuntu/libxmltok?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
