RHSA-2022:7811HighCVSS 9.8

Red Hat Security Advisory: mingw-expat security update

Published
November 8, 2022
Last Modified
June 29, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2022-23990 — expat: integer overflow in the doProlog function CVE-2022-25235 — expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution CVE-2022-25236 — expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution CVE-2022-25313 — expat: Stack exhaustion in doctype parsing CVE-2022-25314 — expat: Integer overflow in copyString() CVE-2022-25315 — expat: Integer overflow in storeRawNames()

🔗 References (10)