First published: Mon Oct 24 2022(Updated: )
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/expat | <=2.2.6-2+deb10u4 | 2.2.6-2+deb10u6 2.2.10-2+deb11u5 2.5.0-1 2.5.0-2 |
debian/expat | <=2.2.10-2<=2.4.9-1 | 2.5.0-1 2.2.10-2+deb11u5 |
redhat/expat | <0:2.2.5-10.el8_7.1 | 0:2.2.5-10.el8_7.1 |
redhat/expat | <0:2.4.9-1.el9_1.1 | 0:2.4.9-1.el9_1.1 |
redhat/expat | <2.5.0 | 2.5.0 |
Google Android | ||
Libexpat Project Libexpat | <=2.4.9 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
All of | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
NetApp OnCommand Workflow Automation | ||
Netapp Solidfire \& Hci Management Node | ||
All of | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node | ||
Netapp Baseboard Management Controller H300s Firmware | ||
Netapp Baseboard Management Controller H300s | ||
Netapp Baseboard Management Controller H500s Firmware | ||
Netapp Baseboard Management Controller H500s | ||
Netapp Baseboard Management Controller H700s Firmware | ||
Netapp Baseboard Management Controller H700s | ||
Netapp Baseboard Management Controller H410s Firmware | ||
Netapp Baseboard Management Controller H410s | ||
Netapp Baseboard Management Controller H410c Firmware | ||
Netapp Baseboard Management Controller H410c | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-43680 is a use-after-free vulnerability in the Expat package, specifically in the destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
CVE-2022-43680 has a severity level of 7.5 (high).
CVE-2022-43680 affects the expat package in various versions on Debian, Red Hat, Google Android, and other platforms.
To fix CVE-2022-43680, update the affected expat package to the recommended versions provided by the vendor.
More information about CVE-2022-43680 can be found in the references section of the vulnerability report.