Skip to content

libexpat CVE-2022-23852

Moderate
arnaldo2792 published GHSA-q23q-h3vx-q22h Feb 8, 2022

Package

libexpat (bottlerocket)

Affected versions

< 1.6.0

Patched versions

1.6.0

Description

A signed integer overflow was discovered in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. This function is called by XML_Parse internally.

Severity

Moderate

CVE ID

CVE-2022-23852

Weaknesses

No CWEs