CVE-2022-23852

CWE-190Integer Overflow11 documents10 sources
Severity
9.8CRITICAL
EPSS
1.7%
top 17.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 24
Latest updateSep 1

Description

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

Androidplatform/external/expat10:010:2022-09-01+3
Debianexpat< 2.2.10-2+deb11u1+3
NVDtenable/nessus10.0.010.1.1+1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

4
OSV
CVE-2022-23852: In XML_GetBuffer of xmlparse2022-09-01
GHSA
GHSA-h83g-c7g2-6r9h: Expat (aka libexpat) before 22022-02-10
OSV
CVE-2022-23852: Expat (aka libexpat) before 22022-01-24
CVEList
CVE-2022-23852: Expat (aka libexpat) before 22022-01-24

📋Vendor Advisories

5
Android
CVE-2022-23852: Android Security Bulletin 2022-09-01 CVE: CVE-2022-23852 Severity: HIGH Type: EoP Affected AOSP versions: 10, 11, 12, 12L References: A-2212558692022-09-01
Ubuntu
Expat vulnerabilities2022-02-21
Red Hat
expat: Integer overflow in function XML_GetBuffer2022-01-23
Microsoft
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer for configurations with a nonzero XML_CONTEXT_BYTES.2022-01-11
Debian
CVE-2022-23852: expat - Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer...2022
CVE-2022-23852 (CRITICAL CVSS 9.8) | Expat (aka libexpat) before 2.4.4 h | cvebase.io