CVE-2021-46143
medium
CVSS v3
β
CVSS v4 NEW
β
VIR risk
5.5
Description
Moderate: xmlrpc-c security update
Predictions
Exploit likelihood
20%
Patch ETA
β
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Source: Red Hat Errata β Red Hat Inc. Β· View original β Β· Open-Errata-API
Description expat: Integer overflow in doProlog in xmlparse.c CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7expat-0:2.1.0-14.el7_9RHSA-2022:10692022-03-28T00:00:00Z Red Hat Enterprise Linux 8expat-0:2.2.5-4.el8_5.3RHSA-2022:09512022-03-16T00:00:00Z Red Hat Enterprise Linuxβ¦
Description
expat: Integer overflow in doProlog in xmlparse.c
CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | expat-0:2.1.0-14.el7_9 | RHSA-2022:1069 | 2022-03-28T00:00:00Z |
| Red Hat Enterprise Linux 8 | expat-0:2.2.5-4.el8_5.3 | RHSA-2022:0951 | 2022-03-16T00:00:00Z |
| Red Hat Enterprise Linux 8 | xmlrpc-c-0:1.51.0-8.el8 | RHSA-2022:7692 | 2022-11-08T00:00:00Z |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | expat-0:2.2.10-1.el8_2 | RHSA-2025:22871 | 2025-12-09T00:00:00Z |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | expat-0:2.2.10-1.el8_4 | RHSA-2025:22785 | 2025-12-04T00:00:00Z |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | expat-0:2.2.10-1.el8_4 | RHSA-2025:22785 | 2025-12-04T00:00:00Z |
| Red Hat Enterprise Linux 9 | expat-0:2.2.10-12.el9_0 | RHBA-2022:4046 | 2022-05-17T00:00:00Z |
| Red Hat Enterprise Linux 9 | expat-0:2.2.10-12.el9_0 | RHBA-2022:4046 | 2022-05-17T00:00:00Z |
| Text-Only JBCS | expat | RHSA-2022:7144 | 2022-10-26T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | expat | Out of support scope |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope |
| Red Hat Enterprise Linux 6 | xulrunner | Out of support scope |
| Red Hat Enterprise Linux 7 | firefox | Affected |
| Red Hat Enterprise Linux 7 | thunderbird | Affected |
| Red Hat Enterprise Linux 7 | xulrunner | Will not fix |
| Red Hat Enterprise Linux 8 | firefox | Affected |
| Red Hat Enterprise Linux 8 | thunderbird | Affected |
| Red Hat Enterprise Linux 9 | firefox | Not affected |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected |
| Red Hat Enterprise Linux 9 | xmlrpc-c | Affected |
Apply commands
Apply RHSA-2022:1069 for Red Hat Enterprise Linux 7
yum update -y expat
# or:
dnf upgrade -y expat
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 7 | Affected |
| redhat | Red Hat Enterprise Linux 7 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| debian | bookworm | fixed | 2.4.3-1 |
| debian | bullseye | fixed | 2.2.10-2+deb11u1 |
| debian | forky | fixed | 2.4.3-1 |
| debian | sid | fixed | 2.4.3-1 |
| debian | trixie | fixed | 2.4.3-1 |
| sles | affected | | |
| rocky | 8 | fixed | |
| almalinux | 8 | fixed | xmlrpc-c-1.51.0-8.el8.i686.rpm |
References
- https://access.redhat.com/errata/RHBA-2022:4046
- https://security-tracker.debian.org/tracker/CVE-2021-46143
- https://www.suse.com/security/cve/CVE-2021-46143.html
- https://errata.rockylinux.org/RLSA-2022:7692
- https://errata.rockylinux.org/RLSA-2022:0951
- https://access.redhat.com/errata/RHSA-2022:7692
- https://bugzilla.redhat.com/2044455
- https://bugzilla.redhat.com/2044457
- https://bugzilla.redhat.com/2044464
- https://bugzilla.redhat.com/2044467
- https://bugzilla.redhat.com/2044479
- https://bugzilla.redhat.com/2044484
- https://bugzilla.redhat.com/2044488
- https://errata.almalinux.org/8/ALSA-2022-7692.html
- https://access.redhat.com/errata/RHSA-2022:0951
- https://bugzilla.redhat.com/2044451
- https://bugzilla.redhat.com/2044613
- https://bugzilla.redhat.com/2056363
- https://bugzilla.redhat.com/2056366
- https://bugzilla.redhat.com/2056370
- https://errata.almalinux.org/8/ALSA-2022-0951.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.