Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian: DSA-5266-1 Critical Update for Expat Heap Use-After-Free

debian
Calendar Grey October 30, 2022
Debian Logo
Debian Security Advisory DSA-5270-1 outlines an essential glibc update that tackles a buffer overflow vulnerability.
A heap use-after-free vulnerability after overeager destruction of a shared DTD in the XML_ExternalEntityParserCreate function in Expat, an XML parsing C library, may result in den...

Summary

For the stable distribution (bullseye), this problem has been fixed in
version 2.2.10-2+deb11u5.

We recommend that you upgrade your expat packages.

For the detailed security status of expat please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/expat

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: expat
CVE ID: CVE-2022-43680

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here