Skip to content

libexpat CVE-2022-25235

High
webern published GHSA-m5gv-vh63-f8qf Mar 30, 2022

Package

libexpat (bottlerocket)

Affected versions

<1.7.0

Patched versions

1.7.0

Description

Description

A flaw was found in expat. Passing malformed 2- and 3-byte UTF-8 sequences (for example, from start tag names) to the XML processing application on top of expat can lead to arbitrary code execution. This issue is dependent on how invalid UTF-8 is handled inside the XML processor.

Severity

High

CVE ID

CVE-2022-25235

Weaknesses

No CWEs