{"id":"CLSA-2022-1660760528","summary":"Fix CVE(s): CVE-2022-25235, CVE-2022-23990, CVE-2022-22825, CVE-2022-22824, CVE-2022-23852, CVE-2022-25315, CVE-2022-25236, CVE-2021-46143, CVE-2022-25313, CVE-2021-45960, CVE-2022-22826, CVE-2022-22827, CVE-2022-22822, CVE-2022-22823","details":"\n   * SECURITY UPDATE: Stack exhaustion\n     - debian/patches/CVE-2022-25313.patch: prevent\n       stack exhaustion in build_model in expat/lib/xmlparse.c.\n     - debian/patches/fix-build_model-regression.patch: fix build_model\n       regression in expat/lib/xmlparse.c.\n     - CVE-2022-25313\n   * SECURITY UPDATE: Integer overflow\n     - debian/patches/CVE-2022-25315.patch: prevent integer overflow in\n       storeRawNames in expat/lib/xmlparse.c.\n     - CVE-2022-25315\n   * SECURITY UPDATE: relax fix to CVE-2022-25236 with regard to\n     RFC 3986 URI characters and possibly regressions\n     - debian/patches/CVE-2022-25236-3.patch: add a note on namespace URI\n       validation in expat/doc/reference.html, expat/lib/expat.h.\n     - debian/patches/CVE-2022-25236-4.patch: document namespace separator\n       effect right in header expat/lib/expat.h.\n     - debian/patches/CVE-2022-25236-5.patch: cover relaxed fix in tests.\n     - debian/patches/CVE-2022-25236-6.patch: relax fix with regard to\n       RFC 3986 URI characters in expat/lib/xmlparse.c. (LP: #1963903)\n   * fix tests adding XCS definition\n     - debian/patches/fix_test_xcs.patch: in tests/runtests.c.\n   * SECURITY UPDATE: Realloc misbehavior\n     - debian/patches/CVE-2021-45960.patch: detect and prevent troublesome\n       left shifts in function storeAtts in lib/xmlparse.c.\n     - CVE-2021-45960\n   * SECURITY UPDATE: Integer overflow\n     - debian/patches/CVE-2021-46143.patch: prevent integer overflow\n       on m_groupSize in function doProlog in lib/xmlparse.c.\n     - CVE-2021-46143\n   * SECURITY UPDATE: Integer overflow\n     - debian/patches/CVE-2022-22822-to-CVE-2022-22827.patch: prevent integer overflow\n       in multiple places in lib/xmlparse.c.\n     - CVE-2022-22822\n     - CVE-2022-22823\n     - CVE-2022-22824\n     - CVE-2022-22825\n     - CVE-2022-22826\n     - CVE-2022-22827\n   * SECURITY UPDATE: Signed integer overflow\n     - debian/patches/CVE-2022-23852-*.patch: detect and prevent\n       integer overflow in XML_GetBuffer in expat/lib/xmlparse.c and\n       adds test to cover it in tests/runtests.c.\n     - CVE-2022-23852\n   * SECURITY UPDATE: Integer overflow\n     - debian/patches/CVE-2022-23990.patch: prevent integer overflow in\n       doProlog in lib/xmlparse.c.\n     - CVE-2022-23990\n   * SECURITY UPDATE: Incomplete validation encoding\n     - debian/patches/CVE-2022-25235-*.patch: adds missing validation\n       and adds tests in expat/lib/xmltok_impl.c, expat/tests/runtests.c.\n     - CVE-2022-25235\n   * SECURITY UPDATE: Namespace-separator insertions\n     - debian/patches/CVE-2022-25236-*.patch: Protect against malicious\n       namespace declarations in expat/lib/xmlparse.c, expat/tests/runtests.c.\n     - CVE-2022-25236\n   * debian/patches/fixing_tests.patch: fixing tests in order to it work\n     in xenial and oldest releases.","modified":"2026-06-04T10:04:12.695059494Z","published":"2022-08-17T18:22:08Z","upstream":["CVE-2021-45960","CVE-2021-46143","CVE-2022-22822","CVE-2022-22823","CVE-2022-22824","CVE-2022-22825","CVE-2022-22826","CVE-2022-22827","CVE-2022-23852","CVE-2022-23990","CVE-2022-25235","CVE-2022-25236","CVE-2022-25313","CVE-2022-25315"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16_04/CLSA-2022-1660760528"}],"affected":[{"package":{"name":"expat","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/expat?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0-7ubuntu0.16.04.5+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1660760528.json"}},{"package":{"name":"libexpat1","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libexpat1?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0-7ubuntu0.16.04.5+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1660760528.json"}},{"package":{"name":"libexpat1-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libexpat1-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0-7ubuntu0.16.04.5+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1660760528.json"}}],"schema_version":"1.7.5"}