ALAS2-2023-2280

Related Vulnerabilities: CVE-2022-23990   CVE-2022-25313  

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. (CVE-2022-23990) A flaw was found in expat. A stack exhaustion in doctype parsing could be triggered by a file with a large number of opening braces, resulting in a denial of service. (CVE-2022-25313)

ALAS2-2023-2280


Amazon Linux 2 Security Advisory: ALAS-2023-2280
Advisory Release Date: 2023-09-27 22:49 Pacific
Advisory Updated Date: 2023-10-05 22:15 Pacific
Severity: Medium

Issue Overview:

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. (CVE-2022-23990)

A flaw was found in expat. A stack exhaustion in doctype parsing could be triggered by a file with a large number of opening braces, resulting in a denial of service. (CVE-2022-25313)


Affected Packages:

expat


Issue Correction:
Run yum update expat to update your system.

New Packages:
aarch64:
    expat-2.1.0-15.amzn2.0.3.aarch64
    expat-devel-2.1.0-15.amzn2.0.3.aarch64
    expat-static-2.1.0-15.amzn2.0.3.aarch64
    expat-debuginfo-2.1.0-15.amzn2.0.3.aarch64

i686:
    expat-2.1.0-15.amzn2.0.3.i686
    expat-devel-2.1.0-15.amzn2.0.3.i686
    expat-static-2.1.0-15.amzn2.0.3.i686
    expat-debuginfo-2.1.0-15.amzn2.0.3.i686

src:
    expat-2.1.0-15.amzn2.0.3.src

x86_64:
    expat-2.1.0-15.amzn2.0.3.x86_64
    expat-devel-2.1.0-15.amzn2.0.3.x86_64
    expat-static-2.1.0-15.amzn2.0.3.x86_64
    expat-debuginfo-2.1.0-15.amzn2.0.3.x86_64