Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23990

Опубликовано: 26 янв. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

A flaw was found in expat. The vulnerability occurs due to large content in element type declarations when there is an element declaration handler present which leads to an integer overflow. This flaw allows an attacker to inject an unsigned integer, leading to a crash or a denial of service.

Отчет

Red Hat Product Security marked this flaw as Moderate Impact because the vulnerability includes a flaw that is present in a program’s source code but to which no current or theoretically possible, but unproven, exploitation vectors exist or were found during the technical analysis of the flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-expat1Out of support scope
Red Hat Enterprise Linux 6expatOut of support scope
Red Hat Enterprise Linux 7expatOut of support scope
Red Hat Enterprise Linux 7firefoxOut of support scope
Red Hat Enterprise Linux 7thunderbirdOut of support scope
Red Hat Enterprise Linux 8expatWill not fix
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8firefox:flatpak/firefoxNot affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 8thunderbird:flatpak/thunderbirdNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2048356expat: integer overflow in the doProlog function

EPSS

Процентиль: 87%
0.03345
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

CVSS3: 7.5
nvd
больше 3 лет назад

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

CVSS3: 7.5
debian
больше 3 лет назад

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doPro ...

CVSS3: 9.8
github
больше 3 лет назад

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

oracle-oval
больше 3 лет назад

ELSA-2022-9232: expat security update (IMPORTANT)

EPSS

Процентиль: 87%
0.03345
Низкий

6.5 Medium

CVSS3