CVE-2021-46143

medium
Published 2022-05-17 Β· Modified 2022-11-11
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: xmlrpc-c security update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description expat: Integer overflow in doProlog in xmlparse.c CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7expat-0:2.1.0-14.el7_9RHSA-2022:10692022-03-28T00:00:00Z Red Hat Enterprise Linux 8expat-0:2.2.5-4.el8_5.3RHSA-2022:09512022-03-16T00:00:00Z Red Hat Enterprise Linux…

Description

expat: Integer overflow in doProlog in xmlparse.c

CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7expat-0:2.1.0-14.el7_9RHSA-2022:10692022-03-28T00:00:00Z
Red Hat Enterprise Linux 8expat-0:2.2.5-4.el8_5.3RHSA-2022:09512022-03-16T00:00:00Z
Red Hat Enterprise Linux 8xmlrpc-c-0:1.51.0-8.el8RHSA-2022:76922022-11-08T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportexpat-0:2.2.10-1.el8_2RHSA-2025:228712025-12-09T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportexpat-0:2.2.10-1.el8_4RHSA-2025:227852025-12-04T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onexpat-0:2.2.10-1.el8_4RHSA-2025:227852025-12-04T00:00:00Z
Red Hat Enterprise Linux 9expat-0:2.2.10-12.el9_0RHBA-2022:40462022-05-17T00:00:00Z
Red Hat Enterprise Linux 9expat-0:2.2.10-12.el9_0RHBA-2022:40462022-05-17T00:00:00Z
Text-Only JBCSexpatRHSA-2022:71442022-10-26T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6expatOut of support scope
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 6xulrunnerOut of support scope
Red Hat Enterprise Linux 7firefoxAffected
Red Hat Enterprise Linux 7thunderbirdAffected
Red Hat Enterprise Linux 7xulrunnerWill not fix
Red Hat Enterprise Linux 8firefoxAffected
Red Hat Enterprise Linux 8thunderbirdAffected
Red Hat Enterprise Linux 9firefoxNot affected
Red Hat Enterprise Linux 9thunderbirdNot affected
Red Hat Enterprise Linux 9xmlrpc-cAffected

Apply commands

bash fix
Apply RHSA-2022:1069 for Red Hat Enterprise Linux 7
yum update -y expat
# or:
dnf upgrade -y expat

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
debian debianbookwormfixed2.4.3-1
debian debianbullseyefixed2.2.10-2+deb11u1
debian debianforkyfixed2.4.3-1
debian debiansidfixed2.4.3-1
debian debiantrixiefixed2.4.3-1
suse slesaffected
rockylinux rocky8fixed
almalinux almalinux8fixedxmlrpc-c-1.51.0-8.el8.i686.rpm

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.