CVE-2022-22827

CWE-190Integer Overflow12 documents9 sources
Severity
8.8HIGH
EPSS
0.3%
top 48.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 13

Description

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Debianexpat< 2.2.10-2+deb11u1+3
NVDtenable/nessus10.0.010.1.1+1

Also affects: Debian Linux 10.0, 11.0

🔴Vulnerability Details

4
OSV
libxmltok vulnerabilities2022-07-19
GHSA
GHSA-97f8-83vc-c97q: storeAtts in xmlparse2022-02-10
OSV
CVE-2022-22827: storeAtts in xmlparse2022-01-10
CVEList
CVE-2022-22827: storeAtts in xmlparse2022-01-08

📋Vendor Advisories

6
Ubuntu
xmltok library vulnerabilities2025-01-13
Ubuntu
xmltok library vulnerabilities2022-07-19
Ubuntu
Expat vulnerabilities2022-02-21
Red Hat
expat: Integer overflow in storeAtts in xmlparse.c2022-01-15
Microsoft
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.2022-01-11
CVE-2022-22827 (HIGH CVSS 8.8) | storeAtts in xmlparse.c in Expat (a | cvebase.io