cbcvebase.
CVE-2022-23990
published 2022-01-26

CVE-2022-23990: Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.4.3-3 (bookworm)expat 2.4.3-3 (bookworm)
debianlibxmltok< expat 2.4.3-3 (bookworm)expat 2.4.3-3 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
googleandroid
libexpat_projectlibexpat< 2.4.42.4.4
msrccbl2_expat_2.4.8-1_on_cbl_mariner_2.0
msrccm1_expat_2.4.4-1_on_cbl_mariner_1.0
oraclecommunications_metasolv_solution
platformexternal_expat>= 10:0 < 10:2022-09-0110:2022-09-01
platformexternal_expat>= 11:0 < 11:2022-09-0111:2022-09-01
platformexternal_expat>= 12:0 < 12:2022-09-0112:2022-09-01
platformexternal_expat>= 12L:0 < 12L:2022-09-0112L:2022-09-01
siemenssinema_remote_connect_server< 3.13.1
tenablenessus< 8.15.38.15.3
tenablenessus>= 10.0.0 < 10.1.110.1.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH