Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-3582-1 Critical: Expat Buffer Overflow Addressed

debian
Calendar Grey May 18, 2016
Debian Logo
Ubuntu issues security notice USN-1234-1 revealing libxml2 package upgrade to mitigate XML parsing vulnerabilities.
Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing...

Summary

For the stable distribution (jessie), this problem has been fixed in
version 2.1.0-6+deb8u2. Additionally this update refreshes the fix for
CVE-2015-1283 to avoid relying on undefined behavior.

We recommend that you upgrade your expat packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: expat
CVE ID: CVE-2016-0718

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here