Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat CodeReady Workspaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2022:1539 - Security Advisory
Issued:
2022-04-26
Updated:
2022-04-26

RHSA-2022:1539 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: xmlrpc-c security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for xmlrpc-c is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

XML-RPC is a remote procedure call (RPC) protocol that uses XML to encode its calls and HTTP as a transport mechanism. The xmlrpc-c packages provide a network protocol to allow a client program to make a simple RPC (remote procedure call) over the Internet. It converts an RPC into an XML document, sends it to a remote server using HTTP, and gets back the response in XML.

Security Fix(es):

  • expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 2056366 - CVE-2022-25235 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution

CVEs

  • CVE-2022-25235

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
xmlrpc-c-1.51.0-5.el8_1.1.src.rpm SHA-256: 9cff0c8716773a493cfbccc59971346fc4e8f9b0da6dff7db4a2b3ca2ba2d6f2
ppc64le
xmlrpc-c-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: db739c96568a367cd8018f1c49b4b5147def0fe53afcd5b011678d4400301930
xmlrpc-c-apps-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 11e3f5b5e0d836b323efe159f924bd1d3bdcc7e807cd449fdecb7bbea08337a4
xmlrpc-c-c++-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 39cd134d61cf774892b8493e064bce0cad387ab97e4b9021b08936654caf4ca2
xmlrpc-c-client++-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 4ec487cf70f4a7ec2f21780a457c1da4d846a2da91e1c06093812e23c63992de
xmlrpc-c-client-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 318b26b8f7366382b728f40136e664087036348c2026fade888b7217c46ed0c1
xmlrpc-c-client-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: f7a342300d60e1777445187aef9c9b4eb35df5650a7e7876fe478eb53d5f7d1c
xmlrpc-c-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 02466bbf1ede6effdcb7be06472a11ad0848e6cb8a7a5e418629dcf361cb2ea3
xmlrpc-c-debugsource-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 02017eac80ae4220a7533208d4c25fa4d411141bf28855722d38990f1a3a72f4

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
xmlrpc-c-1.51.0-5.el8_1.1.src.rpm SHA-256: 9cff0c8716773a493cfbccc59971346fc4e8f9b0da6dff7db4a2b3ca2ba2d6f2
x86_64
xmlrpc-c-1.51.0-5.el8_1.1.i686.rpm SHA-256: 3468e1e3f7c6736c86ff0c4ee5a7a635e4af453ed96dd6d25236b1b0292d95fc
xmlrpc-c-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: ad99e9e0c4859b142f3895dbf57986cefdceb2e75fe9f721a7a6a3b14942a015
xmlrpc-c-apps-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: a81494fad180d02c5d2081338106067b4bd12fd3e156f68fae1e82543f52465c
xmlrpc-c-apps-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: 33c1290e68a16cdd5c6ca24dd94eca6e3fc21e2fc9897e14b3fb57689be30cd4
xmlrpc-c-c++-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: abb09c9a7a218d26a73b65f1cec7a04d7cacc28d011fcb07c1c0037507fbaa7a
xmlrpc-c-c++-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: f165855ff9d258f55a0fe7841a11cc7f632076bbae380e3c56549c60c1783560
xmlrpc-c-client++-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: c53512b657288414e75255da31f0aaa0451eb4f307cca56364ac9a1a53314dca
xmlrpc-c-client++-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: b1f0ad97dfa03b63b048e49f4de4b8d3ddcc6a891a9cca025f793cf3cfa869be
xmlrpc-c-client-1.51.0-5.el8_1.1.i686.rpm SHA-256: 2e601f4b02f63afcdf1394afb21d698631c63d5b4a824f5da7c26aa3a8281410
xmlrpc-c-client-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: 52ed6d9416640362f0117b8ade78854703344e00752040c7c3c1d644431b378a
xmlrpc-c-client-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: 83193f88200d411a7db11840bb987e3c8e3a3d4abc79b29096f321ef38d6bfbb
xmlrpc-c-client-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: c7f084d052e0c44f6dbbcf7feb6b592ab4c6ef5204412c8ae5b63ad0af5c33d4
xmlrpc-c-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: 135738169d1dd76e86e7e06e9b384690d0860755ab2548a6d66f972809225574
xmlrpc-c-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: a83d6614741224ff772bca281d8dc6ce27dfc4b3d416ca2729006df83f2ab263
xmlrpc-c-debugsource-1.51.0-5.el8_1.1.i686.rpm SHA-256: b0f1297f2dd3a78b416da8e34b45e1882b84816e9335b4a040749ae943eee395
xmlrpc-c-debugsource-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: 1b0276a5362ec75844e89126090b63456eef4dd46928c859092e68b7fcb0dfc3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2022 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter