RHSA-2022:7811: Important: mingw-expat security update
Expat is a C library for parsing XML documents. The mingw-expat packages provide a port of the Expat library for MinGW. <br>The following packages have been upgraded to a later upstream version: mingw-expat (2.4.8). (BZ#2057023, BZ#2057037, BZ#2057127)<br>Security Fix(es):<br><li> expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)</li> <li> expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236)</li> <li> expat: Integer overflow in storeRawNames() (CVE-2022-25315)</li> <li> expat: Stack exhaustion in doctype parsing (CVE-2022-25313)</li> <li> expat: Integer overflow in copyString() (CVE-2022-25314)</li> <li> expat: Integer overflow in the doProlog function (CVE-2022-23990)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:7811?
The severity of RHSA-2022:7811 is categorized as critical.
How do I fix RHSA-2022:7811?
To fix RHSA-2022:7811, upgrade the affected mingw-expat, mingw32-expat, and mingw64-expat packages to version 2.4.8-1.el8.
What packages are affected by RHSA-2022:7811?
The affected packages for RHSA-2022:7811 include mingw-expat, mingw32-expat, and mingw64-expat.
Is RHSA-2022:7811 related to XML parsing vulnerabilities?
Yes, RHSA-2022:7811 addresses security vulnerabilities in the Expat library used for parsing XML documents.
Can I track updates related to RHSA-2022:7811?
Updates related to RHSA-2022:7811 can be tracked through the Red Hat security advisories page.