Stack-based buffer overflow in expat - CVE-2022-25313

 

Stack-based buffer overflow in expat - CVE-2022-25313

Published: February 21, 2022 / Updated: June 17, 2022


Vulnerability identifier: #VU60737
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-25313
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
expat
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
IBM AIX
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud
Anolis OS
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Linux
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
Oracle Solaris
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
Junos OS
openEuler
Fedora
Submariner
IBM PureData System for Operational Analytics
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Dell Secure Connect Gateway
OpenShift Logging
Tenable Nessus
IBM Netezza Analytics for NPS
IBM Robotic Process Automation
IBM Netezza Performance Portal
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Tivoli Monitoring
Red Hat OpenStack
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
expat (Debian package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libexpat1 (Ubuntu package)
lib64expat1 (Ubuntu package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
expat
libexpat1
libexpat1-32bit
expat-debuginfo
expat-debugsource
expat-debuginfo-32bit
libexpat1-debuginfo
libexpat1-debuginfo-32bit
libexpat-devel
libexpat1-32bit-debuginfo
expat-32bit-debuginfo
expat-devel
expat (Red Hat package)
expat-help
mingw-expat
mingw32-expat
mingw64-expat
mingw-expat (Red Hat package)
dev-libs/expat
cflinuxfs3
Telemetry Dashboard
Dell Policy Manager for Secure Connect Gateway (SCG)
Liquidware
IBM supplied MQ Advanced container images
Citrix Workspace App
Webex App VDI
EMC ECS
Dell Data Protection Central
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
IBM Netezza Analytics
VMware Horizon Client
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
NetWorker Management Console
Red Hat Ceph Storage
IBM HTTP Server
IBM WebSphere Application Server
JBoss Core Services
SecurID Authentication Manager
IBM DB2
Cisco Jabber
Cisco Webex Meetings
Red Hat OpenShift Serverless
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
SINEMA Remote Connect Server
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
AirWave Management Platform

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in build_model. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2022-25313

Install updates from vendor's website.

Sources