ALAS2022-2022-028

Related Vulnerabilities: CVE-2022-23852   CVE-2022-23990  

expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity. (CVE-2022-23852) Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. (CVE-2022-23990)

ALAS2022-2022-028


Amazon Linux 2022 Security Advisory: ALAS-2022-028
Advisory Release Date: 2022-02-16 00:53 Pacific
Advisory Updated Date: 2022-02-16 19:14 Pacific
Severity: Medium

Issue Overview:

expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity. (CVE-2022-23852)

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. (CVE-2022-23990)


Affected Packages:

expat


Issue Correction:
Run dnf update --releasever=2022.0.20220215 expat to update your system.

New Packages:
aarch64:
    expat-debuginfo-2.4.4-1.amzn2022.aarch64
    expat-static-2.4.4-1.amzn2022.aarch64
    expat-debugsource-2.4.4-1.amzn2022.aarch64
    expat-2.4.4-1.amzn2022.aarch64
    expat-devel-2.4.4-1.amzn2022.aarch64

i686:
    expat-debugsource-2.4.4-1.amzn2022.i686
    expat-static-2.4.4-1.amzn2022.i686
    expat-2.4.4-1.amzn2022.i686
    expat-debuginfo-2.4.4-1.amzn2022.i686
    expat-devel-2.4.4-1.amzn2022.i686

src:
    expat-2.4.4-1.amzn2022.src

x86_64:
    expat-debugsource-2.4.4-1.amzn2022.x86_64
    expat-2.4.4-1.amzn2022.x86_64
    expat-debuginfo-2.4.4-1.amzn2022.x86_64
    expat-devel-2.4.4-1.amzn2022.x86_64
    expat-static-2.4.4-1.amzn2022.x86_64