CVE-2022-22827: Integer Overflow
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity.
Other sources
Expat could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow of storeAtts in xmlparse.c. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22827?
CVE-2022-22827 is a vulnerability in Expat (libexpat) before version 2.4.3 that allows an integer overflow and can cause process interruption.
What is the severity of CVE-2022-22827?
The severity of CVE-2022-22827 is high, with a CVSS score of 8.8.
How does CVE-2022-22827 affect Expat (libexpat)?
CVE-2022-22827 affects Expat (libexpat) versions before 2.4.3.
What is the impact of CVE-2022-22827?
The highest threat from CVE-2022-22827 is to availability and confidentiality.
How can I fix CVE-2022-22827?
To fix CVE-2022-22827, update Expat (libexpat) to version 2.4.3.