Skip to content

libexpat CVE-2022-43680

Moderate
etungsten published GHSA-fwxw-x96j-mxgm Nov 17, 2022

Package

libexpat (bottlerocket)

Affected versions

< 1.11.0

Patched versions

1.11.0

Description

In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

Severity

Moderate

CVE ID

CVE-2022-43680

Weaknesses

No CWEs