CVE-2022-22824: Integer Overflow
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Other sources
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity.
Expat could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow of defineAttribute in xmlparse.c. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22824?
CVE-2022-22824 is a vulnerability in Expat (libexpat) before 2.4.3, where the defineAttribute function in xmlparse.c is susceptible to an integer overflow.
How does CVE-2022-22824 affect the availability and confidentiality of a system?
CVE-2022-22824 poses a high threat to availability and confidentiality due to the potential for process interruption and unexpected termination.
Which software versions are affected by CVE-2022-22824?
CVE-2022-22824 affects Expat (libexpat) versions before 2.4.3.
What is the severity level of CVE-2022-22824?
CVE-2022-22824 has a severity level of critical with a score of 9.8.
Are there any references regarding CVE-2022-22824?
Yes, you can find references regarding CVE-2022-22824 at the following links: [link1], [link2], [link3].