cbcvebase.
CVE-2022-43680
published 2022-10-24

CVE-2022-43680: In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.5.0-1 (bookworm)expat 2.5.0-1 (bookworm)
debianlibxmltok< expat 2.5.0-1 (bookworm)expat 2.5.0-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
googleandroid
libexpat_projectlibexpat<= 2.4.9
msrcazl3_cmake_3.30.3-6_on_azure_linux_3.0
msrccbl2_expat_2.5.0-1_on_cbl_mariner_2.0
msrccm1_expat_2.5.0-1_on_cbl_mariner_1.0
platformexternal_expat>= 10:0 < 10:2023-02-0110:2023-02-01
platformexternal_expat>= 11:0 < 11:2023-02-0111:2023-02-01
platformexternal_expat>= 12:0 < 12:2023-02-0112:2023-02-01
platformexternal_expat>= 12L:0 < 12L:2023-02-0112L:2023-02-01
platformexternal_expat>= 13:0 < 13:2023-02-0113:2023-02-01

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH