Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian DSA-5770-1: Critical Expat DoS and Code Execute Risks

debian
Calendar Grey September 17, 2024
Debian Logo
Multiple security vulnerabilities found in the Expat XML library could lead to denial of service or arbitrary code execution. Debian users should update their systems.
Shang-Hung Wan discovered multiple vulnerabilities in the Expat XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code

Summary

Shang-Hung Wan discovered multiple vulnerabilities in the Expat
XML parsing C library, which could result in denial of service or
potentially the execution of arbitrary code.

For the stable distribution (bookworm), these problems have been fixed in
version 2.5.0-1+deb12u1.

We recommend that you upgrade your expat packages.

For the detailed security status of expat please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/expat

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: expat
CVE ID: CVE-2024-45490 CVE-2024-45491 CVE-2024-45492

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here