First published: Tue Nov 08 2022(Updated: )
XML-RPC is a remote procedure call (RPC) protocol that uses XML to encode its calls and HTTP as a transport mechanism. The xmlrpc-c packages provide a network protocol to allow a client program to make a simple RPC (remote procedure call) over the Internet. It converts an RPC into an XML document, sends it to a remote server using HTTP, and gets back the response in XML.<br>Security Fix(es):<br><li> expat: Integer overflow in doProlog in xmlparse.c (CVE-2021-46143)</li> <li> expat: Integer overflow in addBinding in xmlparse.c (CVE-2022-22822)</li> <li> expat: Integer overflow in build_model in xmlparse.c (CVE-2022-22823)</li> <li> expat: Integer overflow in defineAttribute in xmlparse.c (CVE-2022-22824)</li> <li> expat: Integer overflow in lookup in xmlparse.c (CVE-2022-22825)</li> <li> expat: Integer overflow in nextScaffoldPart in xmlparse.c (CVE-2022-22826)</li> <li> expat: Integer overflow in storeAtts in xmlparse.c (CVE-2022-22827)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/xmlrpc-c | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-apps-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-apps-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-client | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-client | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-client-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-client-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-debugsource | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-debugsource | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-apps-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-client | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-client-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-debuginfo | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-debugsource | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c | <1.51.0-8.el8.aa | 1.51.0-8.el8.aa |
redhat/xmlrpc-c-apps-debuginfo | <1.51.0-8.el8.aa | 1.51.0-8.el8.aa |
redhat/xmlrpc-c-client | <1.51.0-8.el8.aa | 1.51.0-8.el8.aa |
redhat/xmlrpc-c-client-debuginfo | <1.51.0-8.el8.aa | 1.51.0-8.el8.aa |
redhat/xmlrpc-c-debuginfo | <1.51.0-8.el8.aa | 1.51.0-8.el8.aa |
redhat/xmlrpc-c-debugsource | <1.51.0-8.el8.aa | 1.51.0-8.el8.aa |
redhat/xmlrpc-c-devel | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-devel | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-devel | <1.51.0-8.el8 | 1.51.0-8.el8 |
redhat/xmlrpc-c-devel | <1.51.0-8.el8.aa | 1.51.0-8.el8.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.