CVE-2022-22823: Integer Overflow
buildmodel in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Other sources
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity.
Expat could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow of buildmodel in xmlparse.c. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22823?
CVE-2022-22823 is a vulnerability in the Expat library (libexpat) before version 2.4.3 that allows an integer overflow, leading to process interruption.
What is the severity of CVE-2022-22823?
The severity of CVE-2022-22823 is critical with a CVSS score of 9.8.
Which software is affected by CVE-2022-22823?
The affected software includes Expat (libexpat) versions before 2.4.3, and specific versions of Tenable Nessus, xmlrpc-c, Debian Linux, Siemens SINEMA Remote Connect Server, and various Ubuntu packages (libxmltok, expat, firefox, thunderbird).
What is the remedy for CVE-2022-22823 in Expat (libexpat)?
The remedy for CVE-2022-22823 in Expat (libexpat) is to update to version 2.4.3.
Where can I find more information about CVE-2022-22823?
You can find more information about CVE-2022-22823 at the following references: [GitHub](https://github.com/libexpat/libexpat/pull/539), [Openwall](http://www.openwall.com/lists/oss-security/2022/01/17/3), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2044465).