CVE-2022-23990

CWE-190Integer Overflow11 documents10 sources
Severity
7.5HIGH
EPSS
3.5%
top 12.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26
Latest updateSep 1

Description

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

Androidplatform/external/expat10:010:2022-09-01+3
Debianexpat< 2.2.10-2+deb11u1+3
NVDtenable/nessus10.0.010.1.1+1

Also affects: Debian Linux 10.0, 11.0, Fedora 34, 35

Patches

🔴Vulnerability Details

4
OSV
CVE-2022-23990: In closeString of xmlparse2022-09-01
GHSA
GHSA-r3g2-gw56-v728: Expat (aka libexpat) before 22022-02-10
OSV
CVE-2022-23990: Expat (aka libexpat) before 22022-01-26
CVEList
CVE-2022-23990: Expat (aka libexpat) before 22022-01-26

📋Vendor Advisories

6
Android
CVE-2022-23990: Android Security Bulletin 2022-09-01 CVE: CVE-2022-23990 Severity: HIGH Type: EoP Affected AOSP versions: 10, 11, 12, 12L References: A-2212566782022-09-01
Oracle
Oracle Oracle Communications Applications Risk Matrix: User Interface (LibExpat) — CVE-2022-239902022-04-15
Ubuntu
Expat vulnerabilities2022-02-21
Red Hat
expat: integer overflow in the doProlog function2022-01-26
Microsoft
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.2022-01-11
CVE-2022-23990 (HIGH CVSS 7.5) | Expat (aka libexpat) before 2.4.4 h | cvebase.io