Lucene search

K
f5F5F5:K91589041
HistoryMay 01, 2022 - 12:00 a.m.

K91589041 : Expat vulnerabilities CVE-2021-45960, CVE-2022-22825, CVE-2022-22826, and CVE-2022-22827

2022-05-0100:00:00
my.f5.com
61
expat
xml
parsing
cve-2021-45960
cve-2022-22825
cve-2022-22826
cve-2022-22827
buffer over-read

AI Score

9.4

Confidence

High

EPSS

0.013

Percentile

86.4%

Security Advisory Description

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Impact

A remote attacker could send specially crafted XML which, when parsed by an application using the Expat library, would result in a buffer over-read and cause the application to stop responding.