Code Injection in expat - CVE-2022-25235

 

Code Injection in expat - CVE-2022-25235

Published: February 21, 2022 / Updated: June 17, 2022


Vulnerability identifier: #VU60736
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-25235
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
expat
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for Scientific Computing
IBM AIX
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
Oracle Solaris
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
Junos OS
openEuler
Fedora
AFF66X FW
AFS66X-S
AFS660-C
AFS66X-B
AFS670-V20
AFS67X
AFS65X
AFR677
cflinuxfs3
Telemetry Dashboard
Dell Policy Manager for Secure Connect Gateway (SCG)
Liquidware
Citrix Workspace App
Webex App VDI
EMC ECS
XtremIO X2
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
elfutils (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
expat (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
expat (Debian package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
thunderbird (Red Hat package)
firefox (Red Hat package)
lib64expat1 (Ubuntu package)
ayttm (Ubuntu package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
xmlrpc-c (Ubuntu package)
xmlrpc-c (Red Hat package)
xmlrpc-c
xmlrpc-c-client++
xmlrpc-c-client
expat
libexpat1
libexpat1-32bit
expat-debuginfo
expat-debugsource
expat-static
expat-devel
libexpat1-debuginfo-32bit
expat-debuginfo-32bit
libexpat1-debuginfo
libexpat-devel
libexpat1 (Ubuntu package)
libexpat1-32bit-debuginfo
expat-32bit-debuginfo
expat-help
mingw-expat
swish-e (Ubuntu package)
mingw32-expat
mingw64-expat
mingw-expat (Red Hat package)
dev-libs/expat
coin3 (Ubuntu package)
insighttoolkit (Ubuntu package)
redhat-virtualization-host-productimg (Red Hat package)
mozjs78-debugsource
mozjs78-devel
mozjs78
mozjs78-debuginfo
mozjs78-help
firefox-debuginfo
mozilla-crashreporter-firefox-debuginfo
firefox-debugsource
firefox
thunderbird
IBM PureData System for Operational Analytics
Red Hat Advanced Cluster Management for Kubernetes
Oracle VM Server for x86
Dell Secure Connect Gateway
IBM Rational ClearCase
Tenable Nessus
IBM Netezza Analytics for NPS
Netcool Operations Insight
IBM Netezza Performance Portal
Session Smart Router
IBM Tivoli Monitoring
Steel Belted Radius Carrier Edition
Red Hat OpenShift GitOps
IBM QRadar Network Security
IBM QRadar Network Packet Capture
Harbor
Red Hat Virtualization
OpenShift Virtualization
Red Hat OpenShift Serverless
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
NetWorker Management Console
IBM Netezza Analytics
Red Hat OpenShift Container Platform
IBM Edge Application Manager
Nessus Network Monitor
VMware Horizon Client
Migration Toolkit for Containers
Red Hat Virtualization Host
Contrail Networking
IBM WebSphere Application Server
JBoss Core Services
IBM HTTP Server
SecurID Authentication Manager
IBM DB2
Cisco Jabber
Cisco Webex Meetings
SINEMA Remote Connect Server
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
AirWave Management Platform
Juniper Junos Space

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to the affected application lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2022-25235

Install updates from vendor's website.

Sources