CVE-2022-23990: Integer Overflow
A flaw was found in expat. The vulnerability occurs due to large content in element type declarations when there is an element declaration handler present which leads to an integer overflow. This flaw allows an attacker to inject an unsigned integer, leading to a crash or a denial of service.
Other sources
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the doProlog function. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mingw-expatto a version that resolves this vulnerability.Fixed in 0:2.4.8-1.el8 - Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.2.10-2+deb11u5Fixed in 2.2.10-2+deb11u6Fixed in 2.5.0-1+deb12u1Fixed in 2.7.1-1 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 2.4.4 - Upgrade
Upgrade
expat (libexpat)to a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-23990.
What is the severity of CVE-2022-23990?
The severity of CVE-2022-23990 is high with a severity value of 7.5.
What is the affected software of CVE-2022-23990?
The affected software of CVE-2022-23990 includes expat, mingw-expat, Ubuntu expat, Firefox, Debian expat, Tenable Nessus, Oracle Communications Metasolv Solution, Google Android, Siemens SINEMA Remote Connect Server, and Fedora.
How do I fix CVE-2022-23990 on Red Hat?
To fix CVE-2022-23990 on Red Hat, update expat to version 2.4.4 or later.
Are there any references for CVE-2022-23990?
Yes, you can find references for CVE-2022-23990 at the following links: [GitHub](https://github.com/libexpat/libexpat/pull/551), [Red Hat Bugzilla 1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2050215), [Red Hat Bugzilla 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2050214).