elsa-2022-9359
oracle_linux
Description
[2.0.1-13.0.1] - Prevent integer overflow in storeRawNames [CVE-2022-25315][Orabug: 34059442] - Add missing validation of encoding [CVE-2022-25235][Orabug: 34059442] - Protect against malicious namespace declarations [CVE-2022-25236][Orabug: 34059442]
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2022-25236",
"CVE-2022-25235",
"CVE-2022-25315"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[2.0.1-13.0.1]\n- Prevent integer overflow in storeRawNames [CVE-2022-25315][Orabug: 34059442]\n- Add missing validation of encoding [CVE-2022-25235][Orabug: 34059442]\n- Protect against malicious namespace declarations [CVE-2022-25236][Orabug: 34059442]",
"id": "ELSA-2022-9359",
"ovalId": "oval:com.oracle.elsa:def:20229359",
"source": "oracle_linux",
"title": "ELSA-2022-9359: expat security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2022-9359.html"
}