Lucene search

K
f5F5F5:K23421535
HistoryMay 01, 2022 - 12:00 a.m.

K23421535 : Expat vulnerabilities CVE-2022-22822, CVE-2022-22823, and CVE-2022-22824

2022-05-0100:00:00
my.f5.com
127

9.4 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.6%

Security Advisory Description

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Impact

A remote attacker could send specially crafted XML which, when parsed by an application using the Expat library, would result in a buffer over-read and cause the application to stop responding.