cbcvebase.
CVE-2022-22822
published 2022-01-10

CVE-2022-22822: addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.4.3-1 (bookworm)expat 2.4.3-1 (bookworm)
debianlibxmltok< expat 2.4.3-1 (bookworm)expat 2.4.3-1 (bookworm)
googleandroid
libexpat_projectlibexpat< 2.4.32.4.3
msrccbl2_expat_2.4.3-1_on_cbl_mariner_2.0
paloaltopan-os
platformexternal_expat>= 10:0 < 10:2022-09-0110:2022-09-01
platformexternal_expat>= 11:0 < 11:2022-09-0111:2022-09-01
platformexternal_expat>= 12:0 < 12:2022-09-0112:2022-09-01
platformexternal_expat>= 12L:0 < 12L:2022-09-0112L:2022-09-01
siemenssinema_remote_connect_server< 3.13.1
tenablenessus< 8.15.38.15.3
tenablenessus>= 10.0.0 < 10.1.110.1.1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL