QID 377731
Date Published: 2022-11-02
QID 377731: F5 BIG-IP Expat Vulnerability cve-2022-40674 (K44454157)
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.CVE-2022-40674
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.8
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker may be able to use crafted XML to reference previously freed memory, leading to data corruption or the execution of arbitrary code.
Solution
For more information about patch details please refer to K44454157
Vendor References
- K44454157 -
support.f5.com/csp/article/K44454157
CVEs related to QID 377731
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K44454157 |
|