CVE-2022-22824

CWE-190Integer Overflow11 documents8 sources
Severity
9.8CRITICAL
EPSS
0.4%
top 37.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 13

Description

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Debianexpat< 2.2.10-2+deb11u1+3
NVDtenable/nessus10.0.010.1.1+1
Ubuntulibxmltok< 1.2-3ubuntu0.16.04.1~esm2+3

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

4
OSV
libxmltok vulnerabilities2022-07-19
GHSA
GHSA-5pj8-9wmw-j96m: defineAttribute in xmlparse2022-02-10
OSV
CVE-2022-22824: defineAttribute in xmlparse2022-01-10
CVEList
CVE-2022-22824: defineAttribute in xmlparse2022-01-08

📋Vendor Advisories

6
Ubuntu
xmltok library vulnerabilities2025-01-13
Ubuntu
xmltok library vulnerabilities2022-07-19
Ubuntu
Expat vulnerabilities2022-02-21
Red Hat
expat: Integer overflow in defineAttribute in xmlparse.c2022-01-15
Microsoft
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.2022-01-11
CVE-2022-22824 (CRITICAL CVSS 9.8) | defineAttribute in xmlparse.c in Ex | cvebase.io