cbcvebase.
CVE-2022-22824
published 2022-01-10

CVE-2022-22824: defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.4.3-1 (bookworm)expat 2.4.3-1 (bookworm)
debianlibxmltok< expat 2.4.3-1 (bookworm)expat 2.4.3-1 (bookworm)
libexpat_projectlibexpat< 2.4.32.4.3
msrccbl2_expat_2.4.3-1_on_cbl_mariner_2.0
paloaltopan-os
siemenssinema_remote_connect_server< 3.13.1
tenablenessus< 8.15.38.15.3
tenablenessus>= 10.0.0 < 10.1.110.1.1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL