USN-5455-1
Vulnerability Summary
Timeline
Description
libxmltok vulnerabilities Tim Boddy, Gustavo Grieco and others discovered that Expat, that is integrated in xmltok library, incorrectly handled certain files. An attacker could possibly use these issues to cause a denial of service, or possibly execute arbitrary code. These issues were only addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283, CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827) It was discovered that Expat, that is integrated in xmltok library, incorrectly handled encoding validation of certain files. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-25235) It was discovered that Expat, that is integrated in xmltok library, incorrectly handled namespace URIs of certain files. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-25236)
Affected Systems
- ubuntu•libxmltok
< 1.2-3ubuntu0.16.04.1~esm2 | < 1.2-4ubuntu0.18.04.1~esm1 | < 1.2-4ubuntu0.20.04.1~esm1 | < 1.2-4ubuntu0.22.04.1~esm1
References (16)
- https://ubuntu.com/security/notices/USN-5455-1
- https://ubuntu.com/security/CVE-2012-1148
- https://ubuntu.com/security/CVE-2015-1283
- https://ubuntu.com/security/CVE-2016-0718
- https://ubuntu.com/security/CVE-2016-4472
- https://ubuntu.com/security/CVE-2018-20843
- https://ubuntu.com/security/CVE-2019-15903
- https://ubuntu.com/security/CVE-2021-46143
- https://ubuntu.com/security/CVE-2022-22822
- https://ubuntu.com/security/CVE-2022-22823
- https://ubuntu.com/security/CVE-2022-22824
- https://ubuntu.com/security/CVE-2022-22825
- https://ubuntu.com/security/CVE-2022-22826
- https://ubuntu.com/security/CVE-2022-22827
- https://ubuntu.com/security/CVE-2022-25235
- https://ubuntu.com/security/CVE-2022-25236