elsa-2022-1069

oracle_linux
Description

[2.1.0-14.0.1] - lib: Prevent integer overflow in doProlog [CVE-2022-23990][Orabug: 33910302] [2.1.0-14] - Fix multiple CVEs - CVE-2022-25236 expat: namespace-separator characters in 'xmlns[:prefix]' attribute values can lead to arbitrary code execution - CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution - CVE-2022-25315 expat: integer overflow in storeRawNames() - Resolves: CVE-2022-25236 - Resolves: CVE-2022-25235 - Resolves: CVE-2022-25315 [2.1.0-13] - Fix multiple CVEs - CVE-2022-23852 expat: integer overflow in function XML_GetBuffer - CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat - CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c - CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c - CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c - CVE-2022-22825 Integer overflow in lookup in xmlparse.c - CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c - CVE-2022-22823 Integer overflow in build_model in xmlparse.c - CVE-2022-22822 Integer overflow in addBinding in xmlparse.c - Resolves: CVE-2022-23852 - Resolves: CVE-2021-45960 - Resolves: CVE-2021-46143 - Resolves: CVE-2022-22827 - Resolves: CVE-2022-22826 - Resolves: CVE-2022-22825 - Resolves: CVE-2022-22824 - Resolves: CVE-2022-22823 - Resolves: CVE-2022-22822

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2022-25315",
    "CVE-2021-46143",
    "CVE-2022-22826",
    "CVE-2022-22827",
    "CVE-2021-45960",
    "CVE-2022-22822",
    "CVE-2022-25235",
    "CVE-2022-22824",
    "CVE-2022-25236",
    "CVE-2022-22825",
    "CVE-2022-22823",
    "CVE-2022-23852"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.1.0-14.0.1]\n- lib: Prevent integer overflow in doProlog [CVE-2022-23990][Orabug: 33910302]\n\n[2.1.0-14]\n- Fix multiple CVEs\n- CVE-2022-25236 expat: namespace-separator characters in 'xmlns[:prefix]' attribute values can lead to arbitrary code execution\n- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution\n- CVE-2022-25315 expat: integer overflow in storeRawNames()\n- Resolves: CVE-2022-25236\n- Resolves: CVE-2022-25235\n- Resolves: CVE-2022-25315\n\n[2.1.0-13]\n- Fix multiple CVEs\n- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer\n- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat\n- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c\n- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c\n- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c\n- CVE-2022-22825 Integer overflow in lookup in xmlparse.c\n- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c\n- CVE-2022-22823 Integer overflow in build_model in xmlparse.c\n- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c\n- Resolves: CVE-2022-23852\n- Resolves: CVE-2021-45960\n- Resolves: CVE-2021-46143\n- Resolves: CVE-2022-22827\n- Resolves: CVE-2022-22826\n- Resolves: CVE-2022-22825\n- Resolves: CVE-2022-22824\n- Resolves: CVE-2022-22823\n- Resolves: CVE-2022-22822",
  "id": "ELSA-2022-1069",
  "ovalId": "oval:com.oracle.elsa:def:20221069",
  "source": "oracle_linux",
  "title": "ELSA-2022-1069:  expat security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2022-1069.html"
}
View JSON API Download JSON