CVE-2022-25313Uncontrolled Recursion in Project Libexpat

Severity
6.5MEDIUMNVD
OSV9.8
EPSS
0.1%
top 67.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18
Latest updateMar 10

Description

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Also affects: Debian Linux 10.0, 11.0, Fedora 34, 35

Patches

🔴Vulnerability Details

4
OSV
expat vulnerabilities and regression2022-03-10
GHSA
GHSA-3gf2-723m-w3fv: In Expat (aka libexpat) before 22022-02-19
OSV
CVE-2022-25313: In Expat (aka libexpat) before 22022-02-18
CVEList
CVE-2022-25313: In Expat (aka libexpat) before 22022-02-18

📋Vendor Advisories

4
Ubuntu
Expat vulnerabilities and regression2022-03-10
Red Hat
expat: Stack exhaustion in doctype parsing2022-02-19
Microsoft
In Expat (aka libexpat) before 2.4.5 an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.2022-02-08
Debian
CVE-2022-25313: expat - In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion i...2022
CVE-2022-25313 — Uncontrolled Recursion | cvebase