CVE-2022-23852
published 2022-01-24CVE-2022-23852: Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.52%
90.5th percentile
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | expat | < expat 2.4.3-2 (bookworm) | expat 2.4.3-2 (bookworm) |
| debian | libxmltok | < expat 2.4.3-2 (bookworm) | expat 2.4.3-2 (bookworm) |
| android | — | — | |
| libexpat_project | libexpat | < 2.4.4 | 2.4.4 |
| msrc | cbl2_expat_2.4.8-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_expat_2.4.4-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_metasolv_solution | — | — |
| paloalto | pan-os | — | — |
| platform | external_expat | >= 10:0 < 10:2022-09-01 | 10:2022-09-01 |
| platform | external_expat | >= 11:0 < 11:2022-09-01 | 11:2022-09-01 |
| platform | external_expat | >= 12:0 < 12:2022-09-01 | 12:2022-09-01 |
| platform | external_expat | >= 12L:0 < 12L:2022-09-01 | 12L:2022-09-01 |
| siemens | sinema_remote_connect_server | < 3.1 | 3.1 |
| tenable | nessus | < 8.15.3 | 8.15.3 |
| tenable | nessus | >= 10.0.0 < 10.1.1 | 10.1.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
CISA ICS
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
cisa_ics·2023-10-05·CVSS 8.8
[HIGH] Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
ICS Advisory
##
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
Release DateOctober 05, 2023
Alert CodeICSA-23-278-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFS65x, AFF66x, AFS67x, AFR67x Series
- Vulnerabilities: Incorrect Calculation, Integer Overflow or Wraparound, Improper Encoding or Escaping of Output, Exposure of Resource to Wrong Sphere
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities by an attacker could have a high impact on availability, integrity, and confidentiality of the targeted devices.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Hitachi Energy products and versions are affecte
Android
CVE-2022-23852: Android Security Bulletin 2022-09-01
CVE: CVE-2022-23852
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-221255869
vendor_android·2022-09-01·CVSS 9.8
CVE-2022-23852 [CRITICAL] CVE-2022-23852: Android Security Bulletin 2022-09-01
CVE: CVE-2022-23852
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-221255869
Android Security Bulletin 2022-09-01
CVE: CVE-2022-23852
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-221255869
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-06-16·CVSS 3.7
[LOW] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-17
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, disclose information, or allow code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- Siemens SINEMA Remote Connect Server: All v
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2022-02-21
CVE-2022-22823 Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
expat: Integer overflow in function XML_GetBuffer
vendor_redhat·2022-01-23·CVSS 9.8
CVE-2022-23852 [CRITICAL] CWE-190 expat: Integer overflow in function XML_GetBuffer
expat: Integer overflow in function XML_GetBuffer
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity.
Package: expat (Red Hat Enterprise Linux 6) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Package: xulrunner (Red Hat Enterprise Linux 6) - Out of support scope
Package: f
Microsoft
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer for configurations with a nonzero XML_CONTEXT_BYTES.
vendor_msrc·2022-01-11·CVSS 9.8
CVE-2022-23852 [CRITICAL] CWE-190 Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer for configurations with a nonzero XML_CONTEXT_BYTES.
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer for configurations with a nonzero XML_CONTEXT_BYTES.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Act
Debian
CVE-2022-23852: expat - Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer...
vendor_debian·2022·CVSS 9.8
CVE-2022-23852 [CRITICAL] CVE-2022-23852: expat - Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer...
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
Scope: local
bookworm: resolved (fixed in 2.4.3-2)
bullseye: resolved (fixed in 2.2.10-2+deb11u1)
forky: resolved (fixed in 2.4.3-2)
sid: resolved (fixed in 2.4.3-2)
trixie: resolved (fixed in 2.4.3-2)
OSV
CVE-2022-23852: In XML_GetBuffer of xmlparse
osv·2022-09-01
CVE-2022-23852 CVE-2022-23852: In XML_GetBuffer of xmlparse
In XML_GetBuffer of xmlparse.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA
GHSA-h83g-c7g2-6r9h: Expat (aka libexpat) before 2
ghsa_unreviewed·2022-02-10
CVE-2022-23852 [CRITICAL] CWE-190 GHSA-h83g-c7g2-6r9h: Expat (aka libexpat) before 2
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
OSV
CVE-2022-23852: Expat (aka libexpat) before 2
osv·2022-01-24·CVSS 9.8
CVE-2022-23852 [CRITICAL] CVE-2022-23852: Expat (aka libexpat) before 2
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
No detection rules found.
No public exploits indexed.
Bugzilla
Recent expat CVEs
bugzilla·2022-02-10·CVSS 8.8
[HIGH] Recent expat CVEs
Recent expat CVEs
Lately some expat CVEs popped up [1], the expat is sandboxed in the version 96+
but the ESR seems not to be covered. Could you please investigate if the vulnerabilities has any relevancy for the Firefox?
[1] https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=expat&search_type=all&isCpeNameSearch=false
Discussion:
[Tracking Requested - why for this release]: possible sec issues
---
Bobby, do you think RLBoxing expat on ESR was feasible?
(as a possible alternative to updating expat)
---
* CVE-2021-45960, CVE-2021-46143, CVE-2022-22822 to CVE-2022-22827: needs to be verified, but on first glance I don't think we allow enough data into the parser to hit these.
* CVE-2022-23852: doesn't affect us, only affects "configurations with a n
Bugzilla
CVE-2022-23852 expat: Integer overflow in function XML_GetBuffer
bugzilla·2022-01-24·CVSS 9.8
CVE-2022-23852 [CRITICAL] CVE-2022-23852 expat: Integer overflow in function XML_GetBuffer
CVE-2022-23852 expat: Integer overflow in function XML_GetBuffer
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
PR: https://github.com/libexpat/libexpat/pull/550
Reference: https://bugzilla.suse.com/1195054
Discussion:
Created expat tracking bugs for this issue:
Affects: fedora-all [bug 2052320]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2022:0951 https://access.redhat.com/errata/RHSA-2022:0951
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2022:1069 https://access.redhat.com/errata/RHSA-2022:1069
---
This bug is now closed. Further updates for individual products will be reflected on t
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/550https://lists.debian.org/debian-lts-announce/2022/03/msg00007.htmlhttps://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220217-0001/https://www.debian.org/security/2022/dsa-5073https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.tenable.com/security/tns-2022-05https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/550https://lists.debian.org/debian-lts-announce/2022/03/msg00007.htmlhttps://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220217-0001/https://www.debian.org/security/2022/dsa-5073https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.tenable.com/security/tns-2022-05
2022-01-24
Published