CVE-2022-25315
Severity
9.8CRITICAL
EPSS
7.7%
top 8.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 18
Latest updateApr 15
Description
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages5 packages
Also affects: Debian Linux 10.0, 11.0, Fedora 34, 35
Patches
🔴Vulnerability Details
3📋Vendor Advisories
7Oracle
▶
Oracle▶
Oracle Oracle Fusion Middleware Risk Matrix: Outside In Filters (LibExpat) — CVE-2022-25315↗2022-10-15