xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
No history.
Information
Published : 2022-02-16 01:15
Updated : 2025-05-05 17:18
NVD link : CVE-2022-25235
Mitre link : CVE-2022-25235
CVE.ORG link : CVE-2022-25235
JSON object : View
Products Affected
siemens
- sinema_remote_connect_server
oracle
- zfs_storage_appliance_kit
- http_server
fedoraproject
- fedora
libexpat_project
- libexpat
debian
- debian_linux
CWE
CWE-116
Improper Encoding or Escaping of Output