Severity
9.8CRITICAL
EPSS
7.7%
top 8.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18
Latest updateApr 15

Description

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Debianexpat< 2.2.10-2+deb11u2+3
NVDoracle/http_server12.2.1.3.0, 12.2.1.4.0+1

Also affects: Debian Linux 10.0, 11.0, Fedora 34, 35

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8w4r-jhg8-8rvj: In Expat (aka libexpat) before 22022-02-19
OSV
CVE-2022-25315: In Expat (aka libexpat) before 22022-02-18
CVEList
CVE-2022-25315: In Expat (aka libexpat) before 22022-02-18

📋Vendor Advisories

7
Oracle
Oracle Oracle Communications Risk Matrix: Platform (LibExpat) — CVE-2022-253152023-04-15
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (LibExpat) — CVE-2022-253152023-01-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Outside In Filters (LibExpat) — CVE-2022-253152022-10-15
Ubuntu
Expat vulnerabilities and regression2022-03-10
Red Hat
expat: Integer overflow in storeRawNames()2022-02-19