USN-7199-1
Dashboard / Vulnerabilities / USN-7199-1
USN-7199-1
Summary: libxmltok vulnerabilities
Details: It was discovered that Expat, contained within the xmltok library, incorrectly handled malformed XML data. If a user or application were tricked into opening a crafted XML file, an attacker could cause a denial of service, or possibly execute arbitrary code. (CVE-2015-1283, CVE-2016-0718, CVE-2016-4472, CVE-2019-15903) It was discovered that Expat, contained within the xmltok library, incorrectly handled XML data containing a large number of colons, which could lead to excessive resource consumption. If a user or application were tricked into opening a crafted XML file, an attacker could possibly use this issue to cause a denial of service. (CVE-2018-20843) It was discovered that Expat, contained within the xmltok library, incorrectly handled certain input, which could lead to an integer overflow. If a user or application were tricked into opening a crafted XML file, an attacker could possibly use this issue to cause a denial of service. (CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
References: https://ubuntu.com/security/notices/USN-7199-1, https://ubuntu.com/security/CVE-2015-1283, https://ubuntu.com/security/CVE-2016-0718, https://ubuntu.com/security/CVE-2016-4472, https://ubuntu.com/security/CVE-2018-20843, https://ubuntu.com/security/CVE-2019-15903, https://ubuntu.com/security/CVE-2021-46143, https://ubuntu.com/security/CVE-2022-22822, https://ubuntu.com/security/CVE-2022-22823, https://ubuntu.com/security/CVE-2022-22824, https://ubuntu.com/security/CVE-2022-22825, https://ubuntu.com/security/CVE-2022-22826, https://ubuntu.com/security/CVE-2022-22827
Affected packages
Package
Name: libxmltok
Purl: pkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
