Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia: 2022-0081 Moderate: Expat Code Execution and DoS Threat

mageia
Calendar Grey February 22, 2022
Dist Mageia Esm H88
Revised Expat distributions address Mageia security flaws, reducing risks of code execution and denial of service as of February 2022.
Passing malformed 2- and 3-byte UTF-8 sequences (e.g

Summary

Passing malformed 2- and 3-byte UTF-8 sequences (e.g. from start tag names) to the XML processing application on top of Expat can cause arbitrary damage (e.g. code execution) depending on how invalid UTF-8 is handled inside the XML processor; validation was not their job but Expat's. Exploits with code execution are known to exist. (CVE-2022-25235)
Passing (one or more) namespace separator characters in "xmlns[:prefix]" attribute values made Expat send malformed tag names to the XML processor on top of Expat which can cause arbitrary damage (e.g. code execution) depending on such unexpectable cases are handled inside the XML processor; validation was not their job but Expat's. Exploits with code execution are known to exist. (CVE-2022-25236)
Fix stack exhaustion in doctype parsing that could be triggered by e.g. a 2 megabytes file with a large number of opening braces. Expected impact is denial of service or potentially arbitrary code execution. (CVE-2022-25313)
Fix integer overflow...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=30070

- https://seclists.org/oss-sec/2022/q1/150

- https://ubuntu.com/security/notices/USN-5288-1

- https://www.cve.org/CVERecord?id=CVE-2022-25235

- https://www.cve.org/CVERecord?id=CVE-2022-25236

- https://www.cve.org/CVERecord?id=CVE-2022-25313

- https://www.cve.org/CVERecord?id=CVE-2022-25314

- https://www.cve.org/CVERecord?id=CVE-2022-25315

Resolution

SRPMS

- 8/core/expat-2.2.10-1.3.mga8

Publication date: 22 Feb 2022
URL: https://advisories.mageia.org/MGASA-2022-0081.html
Type: security
CVE: CVE-2022-25235, CVE-2022-25236, CVE-2022-25313, CVE-2022-25314, CVE-2022-25315

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here