Expat security update
Details
| Detail name | Value |
|---|---|
| Changelog Number | 13990 |
| Type | Improvement |
| Status | Resolved |
| Fix Versions | Exasol 8.0.0, Exasol 7.1.6, Exasol 7.0.16 |
| Resolution Date | 2022-02-04 |
Description
Vulnerability in libexpat (CVE-2022-23852) allows a remote attacker to pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the Exasol cluster.
Successful exploitation of this vulnerability may result in compromise of vulnerable system.
Prerequisites
- have valid login credentials
- have CREATE SCRIPT or CREATE ANY SCRIPT system privilege
Mitigation
- revoke create script privileges
- add sanity checks in UDFs parsing XML