Skip to content

Commit

Permalink
Changes: Document CVE-2022-23990
Browse files Browse the repository at this point in the history
  • Loading branch information
hartwork committed Jan 26, 2022
1 parent ede41d1 commit 6e34495
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions expat/Changes
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,18 @@ Release x.x.x xxx xxxxxxx xx xxxx
for when XML_CONTEXT_BYTES is defined to >0 (which is both
common and default).
Impact is denial of service or more.
#551 CVE-2022-23990 -- Fix unsigned integer overflow in function
doProlog triggered by large content in element type
declarations when there is an element declaration handler
present (from a prior call to XML_SetElementDeclHandler).
Impact is denial of service or more.

Bug fixes:
#544 #545 xmlwf: Fix a memory leak on output file opening error

Special thanks to:
hwt0415
Roland Illig
Samanta Navarro
and
Clang LeakSan and the Clang team
Expand Down

0 comments on commit 6e34495

Please sign in to comment.