CVE-2022-43680 | libexpat up to 2.4.9 XML_ExternalEntityParserCreate use after free (Issue 649 / Nessus ID 211295)
A vulnerability classified as critical has been found in libexpat up to 2.4.9. Affected is the function XML_ExternalEntityParserCreate. The manipulation leads to use after free.
This vulnerability is traded as CVE-2022-43680. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.