Skip to content

libexpat CVE-2022-23990

Low
arnaldo2792 published GHSA-jx23-pq2c-7xxh Feb 8, 2022

Package

libexpat (bottlerocket)

Affected versions

< 1.6.0

Patched versions

1.6.0

Description

An unsigned integer overflow was discovered in doProlog, which can be triggered by large content in element type declarations when there is an element declaration handler present (from a prior call to XML_SetElementDeclHandler).

Severity

Low

CVE ID

CVE-2022-23990

Weaknesses

No CWEs