CVE-2022-25235: Input Validation
A flaw was found in expat. Passing malformed 2- and 3-byte UTF-8 sequences (for example, from start tag names) to the XML processing application on top of expat can lead to arbitrary code execution. This issue is dependent on how invalid UTF-8 is handled inside the XML processor.
Other sources
libexpat is vulnerable to a denial of service, caused by improper input validation in xmltokimpl.c. By persuading a victim to open a specially-crafted content with malformed encoding, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
xmltokimpl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
Affected Software
Remediation
Information
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:1309
- RHSA-2022:0824
- RHSA-2022:0850
- RHSA-2022:1069
- RHSA-2022:0818
- RHSA-2022:0845
- RHSA-2022:7811
- RHSA-2022:0951
- RHSA-2022:1643
- RHSA-2022:0815
- RHSA-2022:0847
- RHSA-2022:1068
- RHSA-2022:1539
- RHSA-2022:0816
- RHSA-2022:0843
- RHSA-2022:1070
- RHSA-2022:1540
- RHSA-2022:0817
- RHSA-2022:0853
- RHSA-2022:1012
- RHSA-2022:1644
- RHSA-2022:7144
- RHSA-2022:1263
- RHSA-2022:1053
- IBM-7160471
Frequently Asked Questions
What is the severity of CVE-2022-25235?
The severity of CVE-2022-25235 is classified as critical due to its potential for arbitrary code execution.
How do I fix CVE-2022-25235?
To fix CVE-2022-25235, upgrade expat to version 0:2.0.1-14.el6_10 or higher.
Which software is affected by CVE-2022-25235?
CVE-2022-25235 affects expat, firefox, and thunderbird across various Red Hat distributions.
What impact does CVE-2022-25235 have on my system?
CVE-2022-25235 can lead to arbitrary code execution, potentially compromising system security.
Is there a workaround for CVE-2022-25235?
Updating to the recommended versions of the affected software is the suggested approach to mitigate CVE-2022-25235.