CVE-2022-43680

CVSS V2 None CVSS V3 High 7.5
Description
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Overview
  • CVE ID
  • CVE-2022-43680
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-10-24T14:15:53
  • Last Modified Date
  • 2022-12-02T23:00:55
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* 1 OR 2.4.9
AND
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:netapp:baseboard_management_controller_h300s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:baseboard_management_controller_h300s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:baseboard_management_controller_h500s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:baseboard_management_controller_h500s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:baseboard_management_controller_h700s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:baseboard_management_controller_h700s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:baseboard_management_controller_h410s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:baseboard_management_controller_h410s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:baseboard_management_controller_h410c_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:baseboard_management_controller_h410c:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* 1 OR
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:netapp:hci_compute_node_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:* 0 OR
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • NONE
  • Availability Impact
  • HIGH
  • Base Score
  • 7.5
  • Base Severity
  • HIGH
  • Exploitability Score
  • 3.9
  • Impact Score
  • 3.6
References
Reference URL Reference Tags
https://github.com/libexpat/libexpat/issues/649 Exploit Issue Tracking Patch Third Party Advisory
https://github.com/libexpat/libexpat/pull/616 Exploit Issue Tracking Patch Third Party Advisory
https://github.com/libexpat/libexpat/pull/650 Exploit Issue Tracking Patch Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/10/msg00033.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6/ Mailing List Third Party Advisory
https://security.gentoo.org/glsa/202210-38 Third Party Advisory
https://security.netapp.com/advisory/ntap-20221118-0007/ Third Party Advisory
https://www.debian.org/security/2022/dsa-5266 Third Party Advisory
History
Created Old Value New Value Data Type Notes
2022-10-24 15:00:11 Added to TrackCVE
2022-12-07 11:18:12 2022-10-24T14:15Z 2022-10-24T14:15:53 CVE Published Date updated
2022-12-07 11:18:12 2022-12-02T23:00:55 CVE Modified Date updated
2022-12-07 11:18:12 Analyzed Vulnerability Status updated
2022-12-07 11:18:43 References updated