Show plain JSON{"affected_release": [{"advisory": "RHSA-2022:1309", "cpe": "cpe:/o:redhat:rhel_els:6", "package": "expat-0:2.0.1-14.el6_10", "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support", "release_date": "2022-04-12T00:00:00Z"}, {"advisory": "RHSA-2022:0824", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "firefox-0:91.7.0-3.el7_9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2022-03-10T00:00:00Z"}, {"advisory": "RHSA-2022:0850", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "thunderbird-0:91.7.0-2.el7_9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2022-03-14T00:00:00Z"}, {"advisory": "RHSA-2022:1069", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "expat-0:2.1.0-14.el7_9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2022-03-28T00:00:00Z"}, {"advisory": "RHSA-2022:0818", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "firefox-0:91.7.0-3.el8_5", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2022-03-10T00:00:00Z"}, {"advisory": "RHSA-2022:0845", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "thunderbird-0:91.7.0-2.el8_5", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2022-03-14T00:00:00Z"}, {"advisory": "RHSA-2022:7811", "cpe": "cpe:/a:redhat:enterprise_linux:8::crb", "package": "mingw-expat-0:2.4.8-1.el8", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2022-11-08T00:00:00Z"}, {"advisory": "RHSA-2022:0951", "cpe": "cpe:/o:redhat:enterprise_linux:8", "package": "expat-0:2.2.5-4.el8_5.3", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2022-03-16T00:00:00Z"}, {"advisory": "RHSA-2022:0815", "cpe": "cpe:/a:redhat:rhel_e4s:8.1", "package": "firefox-0:91.7.0-3.el8_1", "product_name": "Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions", "release_date": "2022-03-10T00:00:00Z"}, {"advisory": "RHSA-2022:0847", "cpe": "cpe:/a:redhat:rhel_e4s:8.1", "package": "thunderbird-0:91.7.0-2.el8_1", "product_name": "Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions", "release_date": "2022-03-14T00:00:00Z"}, {"advisory": "RHSA-2022:1068", "cpe": "cpe:/o:redhat:rhel_e4s:8.1", "package": "expat-0:2.2.5-3.el8_1.1", "product_name": "Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions", "release_date": "2022-03-28T00:00:00Z"}, {"advisory": "RHSA-2022:0816", "cpe": "cpe:/a:redhat:rhel_eus:8.2", "package": "firefox-0:91.7.0-3.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Extended Update Support", "release_date": "2022-03-10T00:00:00Z"}, {"advisory": "RHSA-2022:0843", "cpe": "cpe:/a:redhat:rhel_eus:8.2", "package": "thunderbird-0:91.7.0-2.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Extended Update Support", "release_date": "2022-03-14T00:00:00Z"}, {"advisory": "RHSA-2022:1070", "cpe": "cpe:/o:redhat:rhel_eus:8.2", "package": "expat-0:2.2.5-3.el8_2.2", "product_name": "Red Hat Enterprise Linux 8.2 Extended Update Support", "release_date": "2022-03-28T00:00:00Z"}, {"advisory": "RHSA-2022:0817", "cpe": "cpe:/a:redhat:rhel_eus:8.4", "package": "firefox-0:91.7.0-3.el8_4", "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support", "release_date": "2022-03-10T00:00:00Z"}, {"advisory": "RHSA-2022:0853", "cpe": "cpe:/a:redhat:rhel_eus:8.4", "package": "thunderbird-0:91.7.0-2.el8_4", "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support", "release_date": "2022-03-14T00:00:00Z"}, {"advisory": "RHSA-2022:1012", "cpe": "cpe:/o:redhat:rhel_eus:8.4", "package": "expat-0:2.2.5-4.el8_4.2", "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support", "release_date": "2022-03-22T00:00:00Z"}, {"advisory": "RHBA-2022:4046", "cpe": "cpe:/a:redhat:enterprise_linux:9", "package": "expat-0:2.2.10-12.el9_0", "product_name": "Red Hat Enterprise Linux 9", "release_date": "2022-05-17T00:00:00Z"}, {"advisory": "RHBA-2022:4046", "cpe": "cpe:/o:redhat:enterprise_linux:9", "package": "expat-0:2.2.10-12.el9_0", "product_name": "Red Hat Enterprise Linux 9", "release_date": "2022-05-17T00:00:00Z"}, {"advisory": "RHSA-2022:1263", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "redhat-virtualization-host-0:4.3.22-20220330.1.el7_9", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7", "release_date": "2022-04-07T00:00:00Z"}, {"advisory": "RHSA-2022:1053", "cpe": "cpe:/o:redhat:rhev_hypervisor:4.4::el8", "package": "redhat-virtualization-host-0:4.4.10-202203211649_8.5", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 8", "release_date": "2022-03-24T00:00:00Z"}, {"advisory": "RHSA-2022:7144", "cpe": "cpe:/a:redhat:jboss_core_services:1", "package": "expat", "product_name": "Text-Only JBCS", "release_date": "2022-10-26T00:00:00Z"}], "bugzilla": {"description": "expat: Integer overflow in storeRawNames()", "id": "2056363", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2056363"}, "csaw": false, "cvss3": {"cvss3_base_score": "9.8", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "CWE-190->CWE-787", "details": ["In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.", "An integer overflow was found in expat. The issue occurs in storeRawNames() by abusing the m_buffer expansion logic to allow allocations very close to INT_MAX and out-of-bounds heap writes. This flaw can cause a denial of service or potentially arbitrary code execution."], "mitigation": {"lang": "en:us", "value": "There is no known mitigation other than restricting applications using the expat library from processing untrusted XML content. Please update the affected packages as soon as possible."}, "name": "CVE-2022-25315", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Affected", "package_name": "firefox:flatpak/firefox", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Affected", "package_name": "thunderbird:flatpak/thunderbird", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Not affected", "package_name": "xmlrpc-c", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:9", "fix_state": "Not affected", "package_name": "firefox", "product_name": "Red Hat Enterprise Linux 9"}, {"cpe": "cpe:/o:redhat:enterprise_linux:9", "fix_state": "Not affected", "package_name": "thunderbird", "product_name": "Red Hat Enterprise Linux 9"}, {"cpe": "cpe:/o:redhat:enterprise_linux:9", "fix_state": "Not affected", "package_name": "xmlrpc-c", "product_name": "Red Hat Enterprise Linux 9"}], "public_date": "2022-02-19T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2022-25315\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-25315\nhttps://blog.hartwork.org/posts/expat-2-4-5-released/"], "statement": "This flaw affects applications that leverage expat to parse untrusted XML files. Applications that only parse trusted XML files or do not process XML files at all are not affected by this flaw.", "threat_severity": "Important"}