{"cves":["CVE-2022-25235","CVE-2022-22825","CVE-2022-22823","CVE-2022-23852","CVE-2021-45960","CVE-2021-46143","CVE-2022-22822","CVE-2022-22824","CVE-2022-22826","CVE-2022-25236","CVE-2022-22827","CVE-2022-25315"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[2.2.5-4.3]\n- Improve fix for CVE-2022-25236\n- Related: CVE-2022-25236\n\n[2.2.5-4.2]\n- Fix multiple CVEs\n- Resolves: CVE-2022-25236\n- Resolves: CVE-2022-25235\n- Resolves: CVE-2022-25315\n\n[2.2.5-4.1]\n- Fix multiple CVEs\n- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer\n- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat\n- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c\n- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c\n- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c\n- CVE-2022-22825 Integer overflow in lookup in xmlparse.c\n- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c\n- CVE-2022-22823 Integer overflow in build_model in xmlparse.c\n- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c\n- Resolves: CVE-2022-23852\n- Resolves: CVE-2021-45960\n- Resolves: CVE-2021-46143\n- Resolves: CVE-2022-22827\n- Resolves: CVE-2022-22826\n- Resolves: CVE-2022-22825\n- Resolves: CVE-2022-22824\n- Resolves: CVE-2022-22823\n- Resolves: CVE-2022-22822","id":"ELSA-2022-0951","ovalId":"oval:com.oracle.elsa:def:20220951","source":"oracle_linux","title":"ELSA-2022-0951:  expat security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2022-0951.html"}