Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:0178-1

Опубликовано: 25 янв. 2022
Источник: suse-cvrf

Описание

Security update for expat

This update for expat fixes the following issues:

  • CVE-2021-45960: Fixed left shift in the storeAtts function in xmlparse.c that can lead to realloc misbehavior (bsc#1194251).
  • CVE-2021-46143: Fixed integer overflow in m_groupSize in doProlog (bsc#1194362).
  • CVE-2022-22822: Fixed integer overflow in addBinding in xmlparse.c (bsc#1194474).
  • CVE-2022-22823: Fixed integer overflow in build_model in xmlparse.c (bsc#1194476).
  • CVE-2022-22824: Fixed integer overflow in defineAttribute in xmlparse.c (bsc#1194477).
  • CVE-2022-22825: Fixed integer overflow in lookup in xmlparse.c (bsc#1194478).
  • CVE-2022-22826: Fixed integer overflow in nextScaffoldPart in xmlparse.c (bsc#1194479).
  • CVE-2022-22827: Fixed integer overflow in storeAtts in xmlparse.c (bsc#1194480).

Список пакетов

Container bci/bci-init:15.3
libexpat1-2.2.5-3.9.1
Container bci/golang:1.16
libexpat1-2.2.5-3.9.1
Container bci/golang:1.17
libexpat1-2.2.5-3.9.1
Container bci/golang:latest
libexpat1-2.2.5-3.9.1
Container bci/node:12
libexpat1-2.2.5-3.9.1
Container bci/node:14
libexpat1-2.2.5-3.9.1
Container bci/nodejs:latest
libexpat1-2.2.5-3.9.1
Container bci/openjdk-devel:11
libexpat1-2.2.5-3.9.1
Container bci/openjdk:latest
libexpat1-2.2.5-3.9.1
Container bci/python:3
libexpat1-2.2.5-3.9.1
Container bci/ruby:latest
libexpat1-2.2.5-3.9.1
Container caasp/v4/389-ds:1.4.2
libexpat1-2.2.5-3.9.1
Container caasp/v4/cilium:1.6.6
libexpat1-2.2.5-3.9.1
Container caasp/v4/etcd:3.4.13
libexpat1-2.2.5-3.9.1
Container caasp/v4/hyperkube:v1.17.17
libexpat1-2.2.5-3.9.1
Container caasp/v4/k8s-sidecar:0.1.75
libexpat1-2.2.5-3.9.1
Container caasp/v4/prometheus-alertmanager:0.16.2
libexpat1-2.2.5-3.9.1
Container caasp/v4/prometheus-pushgateway:0.6.0
libexpat1-2.2.5-3.9.1
Container caasp/v4/prometheus-server:2.7.1
libexpat1-2.2.5-3.9.1
Container caasp/v4/rsyslog:8.39.0
libexpat1-2.2.5-3.9.1
Container caasp/v4/skuba-tooling:0.1.0
libexpat1-2.2.5-3.9.1
Container ses/6/cephcsi/cephcsi:latest
libexpat1-2.2.5-3.9.1
Container ses/6/rook/ceph:latest
libexpat1-2.2.5-3.9.1
Container ses/7.1/ceph/haproxy:latest
libexpat1-2.2.5-3.9.1
Container ses/7.1/ceph/keepalived:latest
libexpat1-2.2.5-3.9.1
Container ses/7.1/cephcsi/cephcsi:latest
libexpat1-2.2.5-3.9.1
Container ses/7.1/rook/ceph:latest
libexpat1-2.2.5-3.9.1
Container ses/7/cephcsi/cephcsi:latest
libexpat1-2.2.5-3.9.1
Container ses/7/prometheus-webhook-snmp:latest
libexpat1-2.2.5-3.9.1
Container ses/7/rook/ceph:latest
libexpat1-2.2.5-3.9.1
Container suse/pcp:latest
libexpat1-2.2.5-3.9.1
Container suse/rmt-mariadb:latest
libexpat1-2.2.5-3.9.1
Container suse/rmt-nginx:latest
libexpat1-2.2.5-3.9.1
Container suse/sle-micro-rancher/5.2:latest
libexpat1-2.2.5-3.9.1
Container suse/sle-micro/5.1/toolbox:latest
libexpat1-2.2.5-3.9.1
Container suse/sle-micro/5.2/toolbox:latest
libexpat1-2.2.5-3.9.1
Container trento/trento-db:latest
libexpat1-2.2.5-3.9.1
Container trento/trento-runner:latest
libexpat1-2.2.5-3.9.1
Image SLES15-Azure-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-EC2-CHOST-HVM-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-EC2-HVM-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-GCE-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-SAP-Azure
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SAP-Azure-BYOS
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SAP-Azure-LI-BYOS-Production
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SAP-Azure-VLI-BYOS-Production
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SAP-EC2-HVM
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SAP-EC2-HVM-BYOS
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SAP-GCE
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SAP-GCE-BYOS
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-Azure-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-Azure-HPC-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-CHOST-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-CHOST-BYOS-EC2
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-CHOST-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-EC2-HPC-HVM-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-EC2-HVM-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-GCE-BYOS
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAP-Azure
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAP-Azure-BYOS
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAP-EC2-HVM
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAP-EC2-HVM-BYOS
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAP-GCE
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAP-GCE-BYOS
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAPCAL-Azure
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAPCAL-EC2-HVM
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP1-SAPCAL-GCE
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-CHOST-BYOS-Aliyun
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-CHOST-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-CHOST-BYOS-EC2
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-CHOST-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-HPC-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-HPC-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-SAP-Azure
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-SAP-BYOS-Azure
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-SAP-BYOS-EC2-HVM
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-SAP-BYOS-GCE
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-SAP-EC2-HVM
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP2-SAP-GCE
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-CHOST-BYOS-Aliyun
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-CHOST-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-CHOST-BYOS-EC2
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-CHOST-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-CHOST-BYOS-SAP-CCloud
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-EC2-ECS-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-EC2-HVM
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-HPC-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-HPC-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-HPC-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-HPC-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Micro-5-1-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Micro-5-1-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Micro-5-1-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Micro-5-2-BYOS-Azure
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Micro-5-2-BYOS-EC2-HVM
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Micro-5-2-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-Micro-BYOS-GCE
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAP-Azure
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAP-BYOS-Azure
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAP-BYOS-EC2-HVM
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAP-BYOS-GCE
expat-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAP-EC2-HVM
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAP-GCE
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAPCAL-Azure
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAPCAL-EC2-HVM
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
Image SLES15-SP3-SAPCAL-GCE
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
SUSE Enterprise Storage 6
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Enterprise Storage 7
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Micro 5.0
libexpat1-2.2.5-3.9.1
SUSE Linux Enterprise Micro 5.1
libexpat1-2.2.5-3.9.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Server 15 SP1-BCL
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Server 15 SP1-LTSS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Server 15 SP2-BCL
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Server 15 SP2-LTSS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Server 15-LTSS
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Server for SAP Applications 15
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Manager Proxy 4.1
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Manager Retail Branch Server 4.1
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1
SUSE Manager Server 4.1
expat-2.2.5-3.9.1
libexpat-devel-2.2.5-3.9.1
libexpat1-2.2.5-3.9.1
libexpat1-32bit-2.2.5-3.9.1

Описание

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).


Затронутые продукты
Container bci/bci-init:15.3:libexpat1-2.2.5-3.9.1
Container bci/golang:1.16:libexpat1-2.2.5-3.9.1
Container bci/golang:1.17:libexpat1-2.2.5-3.9.1
Container bci/golang:latest:libexpat1-2.2.5-3.9.1

Ссылки

Описание

In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.


Затронутые продукты
Container bci/bci-init:15.3:libexpat1-2.2.5-3.9.1
Container bci/golang:1.16:libexpat1-2.2.5-3.9.1
Container bci/golang:1.17:libexpat1-2.2.5-3.9.1
Container bci/golang:latest:libexpat1-2.2.5-3.9.1

Ссылки

Описание

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.


Затронутые продукты
Container bci/bci-init:15.3:libexpat1-2.2.5-3.9.1
Container bci/golang:1.16:libexpat1-2.2.5-3.9.1
Container bci/golang:1.17:libexpat1-2.2.5-3.9.1
Container bci/golang:latest:libexpat1-2.2.5-3.9.1

Ссылки

Описание

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.


Затронутые продукты
Container bci/bci-init:15.3:libexpat1-2.2.5-3.9.1
Container bci/golang:1.16:libexpat1-2.2.5-3.9.1
Container bci/golang:1.17:libexpat1-2.2.5-3.9.1
Container bci/golang:latest:libexpat1-2.2.5-3.9.1

Ссылки

Описание

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.


Затронутые продукты
Container bci/bci-init:15.3:libexpat1-2.2.5-3.9.1
Container bci/golang:1.16:libexpat1-2.2.5-3.9.1
Container bci/golang:1.17:libexpat1-2.2.5-3.9.1
Container bci/golang:latest:libexpat1-2.2.5-3.9.1

Ссылки

Описание

lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.


Затронутые продукты
Container bci/bci-init:15.3:libexpat1-2.2.5-3.9.1
Container bci/golang:1.16:libexpat1-2.2.5-3.9.1
Container bci/golang:1.17:libexpat1-2.2.5-3.9.1
Container bci/golang:latest:libexpat1-2.2.5-3.9.1

Ссылки

Описание

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.


Затронутые продукты
Container bci/bci-init:15.3:libexpat1-2.2.5-3.9.1
Container bci/golang:1.16:libexpat1-2.2.5-3.9.1
Container bci/golang:1.17:libexpat1-2.2.5-3.9.1
Container bci/golang:latest:libexpat1-2.2.5-3.9.1

Ссылки

Описание

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.


Затронутые продукты
Container bci/bci-init:15.3:libexpat1-2.2.5-3.9.1
Container bci/golang:1.16:libexpat1-2.2.5-3.9.1
Container bci/golang:1.17:libexpat1-2.2.5-3.9.1
Container bci/golang:latest:libexpat1-2.2.5-3.9.1

Ссылки
Уязвимость SUSE-SU-2022:0178-1