CVE-2022-25313 is a stack exhaustion vulnerability in Expat (libexpat) versions prior to 2.4.5, affecting products from vendors like Debian, Fedora, Oracle, and Siemens. An unauthenticated attacker can trigger this by providing a specially crafted DTD element with a large nesting depth, requiring user interaction. Rated Medium (CVSS 6.5), this vulnerability primarily impacts availability (A:H) due to potential denial of service. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.5CPE matchmatch criteria | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.