Expat security update

Details

Detail name Value
Changelog Number 13990
Type Improvement
Status Resolved
Fix Versions Exasol 8.0.0, Exasol 7.1.6, Exasol 7.0.16
Resolution Date 2022-02-04

Description 

Vulnerability in libexpat (CVE-2022-23852) allows a remote attacker to pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the Exasol cluster.

Successful exploitation of this vulnerability may result in compromise of vulnerable system.

Prerequisites

  • have valid login credentials
  • have CREATE SCRIPT or CREATE ANY SCRIPT system privilege

Mitigation

  • revoke create script privileges
  • add sanity checks in UDFs parsing XML