Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 9: DLA-2935-1 Moderate Security Alert for Expat DoS Issues

debian lts
Calendar Grey March 7, 2022
Dist Debian Esm H88
Multiple flaws in Expat can cause service disruption or allow code execution when handling improperly structured XML. Upgrade recommended!
Several vulnerabilities have been discovered in Expat, an XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code, if a malfor...

Summary

For Debian 9 stretch, these problems have been fixed in version
2.2.0-2+deb9u5.

We recommend that you upgrade your expat packages.

For the detailed security status of expat please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/expat

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

Package: expat
Version: 2.2.0-2+deb9u5
CVE ID: CVE-2022-23852 CVE-2022-25235 CVE-2022-25236 CVE-2022-25313
Debian Bug: 1005894 1005895

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here