Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 8 MGASA-2022-0048 Moderate: Expat Integer Overflow

mageia
Calendar Grey February 3, 2022
Dist Mageia Esm H88
Mageia updates expat packages to address critical vulnerabilities, particularly memory corruption. Users are urged to upgrade to the latest versions for enhanced security.
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES

Summary

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. (CVE-2022-23852)
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. (CVE-2022-23990)

References

- https://bugs.mageia.org/show_bug.cgi?id=29985

- https://lists.debian.org/debian-lts-announce/2022/01/msg00032.html

- https://www.cve.org/CVERecord?id=CVE-2022-23852

- https://www.cve.org/CVERecord?id=CVE-2022-23990

Resolution

SRPMS

- 8/core/expat-2.2.10-1.2.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 03 Feb 2022
URL: https://advisories.mageia.org/MGASA-2022-0048.html
Type: security
CVE: CVE-2022-23852, CVE-2022-23990

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here