CVE-2022-23852

Related Vulnerabilities: CVE-2022-23852  

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

Description

The MITRE CVE dictionary describes this issue as:

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

Additional Information

  • Bugzilla 2044613: CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
  • CWE-190: Integer Overflow or Wraparound
  • FAQ: Frequently asked questions about CVE-2022-23852