Skip to content

libexpat CVE-2022-25236

High
webern published GHSA-v95x-cqc2-wxq4 Mar 30, 2022

Package

libexpat (bottlerocket)

Affected versions

<1.7.0

Patched versions

1.7.0

Description

Description

A flaw was found in expat. Passing one or more namespace separator characters in the "xmlns[:prefix]" attribute values made expat send malformed tag names to the XML processor on top of expat. This issue causes arbitrary code execution depending on how unexpected cases are handled inside the XML processor.

Severity

High

CVE ID

CVE-2022-25236

Weaknesses

No CWEs