First published: Mon Jan 23 2023(Updated: )
Expat is a C library for parsing XML documents.<br>Security Fix(es):<br><li> expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (CVE-2022-43680)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/expat | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-debuginfo | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-debuginfo | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-debugsource | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-debugsource | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-devel | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-devel | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-debuginfo | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-debugsource | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat-devel | <2.4.9-1.el9_1.1 | 2.4.9-1.el9_1.1 |
redhat/expat | <2.4.9-1.el9_1.1.aa | 2.4.9-1.el9_1.1.aa |
redhat/expat-debuginfo | <2.4.9-1.el9_1.1.aa | 2.4.9-1.el9_1.1.aa |
redhat/expat-debugsource | <2.4.9-1.el9_1.1.aa | 2.4.9-1.el9_1.1.aa |
redhat/expat-devel | <2.4.9-1.el9_1.1.aa | 2.4.9-1.el9_1.1.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:0337 is classified as moderate.
To fix RHSA-2023:0337, update the expat package to version 2.4.9-1.el9_1.1 or higher.
RHSA-2023:0337 addresses a use-after-free vulnerability caused by improper handling in XML_ExternalEntityParserCreate (CVE-2022-43680).
The affected packages include expat, expat-debuginfo, expat-devel, and expat-debugsource in various architectures.
A restart may not be required, but it is advisable to restart any services using the expat library to ensure the fixes are applied.