QID 354629
Date Published: 2023-01-02
QID 354629: Amazon Linux Security Advisory for xmlrpc-c : AL2012-2022-361
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-25235:
A flaw was found in expat. Passing malformed 2- and 3-byte UTF-8 sequences (for example, from start tag names) to the XML processing application on top of expat can lead to arbitrary code execution. This issue is dependent on how invalid UTF-8 is handled inside the XML processor.
2056366: CVE-2022-25235 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 354629
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2022-361 | Amazon Linux Bare Metal |
|