First published: Thu Jan 12 2023(Updated: )
Expat is a C library for parsing XML documents.<br>Security Fix(es):<br><li> expat: use-after free caused by overeager destruction of a shared DTD in</li> XML_ExternalEntityParserCreate (CVE-2022-43680)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/expat | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-debuginfo | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-debuginfo | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-debugsource | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-debugsource | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-devel | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-devel | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-debuginfo | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-debugsource | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat-devel | <2.2.5-10.el8_7.1 | 2.2.5-10.el8_7.1 |
redhat/expat | <2.2.5-10.el8_7.1.aa | 2.2.5-10.el8_7.1.aa |
redhat/expat-debuginfo | <2.2.5-10.el8_7.1.aa | 2.2.5-10.el8_7.1.aa |
redhat/expat-debugsource | <2.2.5-10.el8_7.1.aa | 2.2.5-10.el8_7.1.aa |
redhat/expat-devel | <2.2.5-10.el8_7.1.aa | 2.2.5-10.el8_7.1.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2023:0103 has been classified as a moderate severity vulnerability.
To fix RHSA-2023:0103, update the expat package to version 2.2.5-10.el8_7.1 or later.
RHSA-2023:0103 affects the expat C library, specifically versions below 2.2.5-10.el8_7.1.
The implications of RHSA-2023:0103 include potential exploitation through a use-after-free condition leading to memory corruption.
Yes, you need to update the expat package along with its related packages like expat-debuginfo, expat-devel, and expat-debugsource.