CVE-2022-22824

Description

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.431

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.2Windows
Multiple vulnerabilities are fixed in IBM HTTP 9.0.5.11Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0.7Windows
expat security update(DSA-5073-1) expat_2.2.6-2+deb10u2_amd64.debLinux
expat security update(DSA-5073-1) expat_2.2.6-2+deb10u2_i386.debLinux
expat security update(DSA-5073-1) Debian_expat_2.2.6-2+deb10u2_amd64.debLinux
expat security update(DSA-5073-1) expat_2.2.10-2+deb11u1_amd64.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.2.5-3ubuntu0.7_i386.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.2.5-3ubuntu0.7_amd64.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.2.9-1ubuntu0.4_i386.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.2.9-1ubuntu0.4_amd64.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.4.1-2ubuntu0.3_i386.debLinux
XML parsing C library (USN-5288-1) libexpat1_2.4.1-2ubuntu0.3_amd64.debLinux
(RHSA-2022:0951) expat security update expat-debugsource-2.2.5-4.el8_5.3.i686.rpmLinux
(RHSA-2022:0951) expat security update expat-debugsource-2.2.5-4.el8_5.3.x86_64.rpmLinux
(RHSA-2022:1069) expat security update expat-2.1.0-14.el7_9.i686.rpmLinux
(RHSA-2022:1069) expat security update expat-2.1.0-14.el7_9.x86_64.rpmLinux
(RHSA-2022:1069) expat security update expat-devel-2.1.0-14.el7_9.i686.rpmLinux
(RHSA-2022:1069) expat security update expat-devel-2.1.0-14.el7_9.x86_64.rpmLinux
(RHSA-2022:1069) expat security update expat-static-2.1.0-14.el7_9.i686.rpmLinux
(RHSA-2022:1069) expat security update expat-static-2.1.0-14.el7_9.x86_64.rpmLinux
Expat update (ELSA-2022-0951) expat-2.2.5-4.el8_5.3.i686.rpmLinux
Expat update (ELSA-2022-0951) expat-2.2.5-4.el8_5.3.x86_64.rpmLinux
Expat-devel update (ELSA-2022-0951) expat-devel-2.2.5-4.el8_5.3.i686.rpmLinux
Expat-devel update (ELSA-2022-0951) expat-devel-2.2.5-4.el8_5.3.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) expat-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) expat-debuginfo-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) expat-debuginfo-32bit-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) expat-debugsource-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) libexpat1-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) libexpat1-32bit-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) libexpat1-debuginfo-2.1.0-21.12.1.x86_64.rpmLinux
SUSE-SU-2022:0179-1(SUSE Linux Enterprise Server 12-SP5 ) libexpat1-debuginfo-32bit-2.1.0-21.12.1.x86_64.rpmLinux
Expat update (ELSA-2022-1069) expat-2.1.0-14.0.1.el7_9.i686.rpmLinux
Expat update (ELSA-2022-1069) expat-2.1.0-14.0.1.el7_9.x86_64.rpmLinux
Expat-devel update (ELSA-2022-1069) expat-devel-2.1.0-14.0.1.el7_9.i686.rpmLinux
Expat-devel update (ELSA-2022-1069) expat-devel-2.1.0-14.0.1.el7_9.x86_64.rpmLinux
Expat-static update (ELSA-2022-1069) expat-static-2.1.0-14.0.1.el7_9.i686.rpmLinux
Expat-static update (ELSA-2022-1069) expat-static-2.1.0-14.0.1.el7_9.x86_64.rpmLinux
xmlrpc-c security update (RLSA-2022:7692) xmlrpc-c-1.51.0-8.el8.i686.rpmLinux
xmlrpc-c security update (RLSA-2022:7692) xmlrpc-c-1.51.0-8.el8.x86_64.rpmLinux
xmlrpc-c security update (RLSA-2022:7692) xmlrpc-c-client-1.51.0-8.el8.i686.rpmLinux
xmlrpc-c security update (RLSA-2022:7692) xmlrpc-c-client-1.51.0-8.el8.x86_64.rpmLinux
Xmlrpc-c update (ELSA-2022-7692) xmlrpc-c-1.51.0-8.el8.i686.rpmLinux
Xmlrpc-c update (ELSA-2022-7692) xmlrpc-c-1.51.0-8.el8.x86_64.rpmLinux
Xmlrpc-c-client update (ELSA-2022-7692) xmlrpc-c-client-1.51.0-8.el8.i686.rpmLinux
Xmlrpc-c-client update (ELSA-2022-7692) xmlrpc-c-client-1.51.0-8.el8.x86_64.rpmLinux
XML Parser Toolkit, runtime libraries (USN-7199-1) libxmltok1t64_1.2-4.1ubuntu3.1_amd64.debLinux
library for rendering vector based animations and art (USN-7198-1) libxmltok1t64_1.2-4.1ubuntu3.1_amd64.debLinux
expat Security Update (ALAS2023-2023-058) expat-2.5.0-1.amzn2023.0.2.x86_64.rpmLinux
expat Security Update (ALAS2023-2023-058) expat-devel-2.5.0-1.amzn2023.0.2.x86_64.rpmLinux
expat Security Update (ALAS2023-2023-058) expat-static-2.5.0-1.amzn2023.0.2.x86_64.rpmLinux
Integer Overflow or Wraparound Vulnerability (CVE-2022-22824)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234