Red Hat Security Advisory: mingw-expat security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2022-23990 — expat: integer overflow in the doProlog function CVE-2022-25235 — expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution CVE-2022-25236 — expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution CVE-2022-25313 — expat: Stack exhaustion in doctype parsing CVE-2022-25314 — expat: Integer overflow in copyString() CVE-2022-25315 — expat: Integer overflow in storeRawNames()
🎯 Affected products6
- Red Hat CodeReady Linux Builder (v. 8)
- mingw-expat-0:2.4.8-1.el8.src as a component of Red Hat CodeReady Linux Builder (v. 8)
- mingw32-expat-0:2.4.8-1.el8.noarch as a component of Red Hat CodeReady Linux Builder (v. 8)
- mingw32-expat-debuginfo-0:2.4.8-1.el8.noarch as a component of Red Hat CodeReady Linux Builder (v. 8)
- mingw64-expat-0:2.4.8-1.el8.noarch as a component of Red Hat CodeReady Linux Builder (v. 8)
- mingw64-expat-debuginfo-0:2.4.8-1.el8.noarch as a component of Red Hat CodeReady Linux Builder (v. 8)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: There is no known mitigation other than restricting applications using the expat library from processing untrusted XML content. Please update the affected packages as soon as possible. Workaround: There is no known mitigation other than restricting applications using the expat library from processing untrusted XML content.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2022:7811
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.7_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048356
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056350
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056354
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056363
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056366
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056370
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_7811.json