SciLinux: CVE-2009-3560 Moderate: expat SL3.x, SL4.x, SL5.x i386/x86_64
Summary
Date: Tue, 8 Dec 2009 11:06:31 -0600Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: expat on SL3.x, SL4.x, SL5.x i386/x86_64Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: expat security updateIssue date: 2009-12-07CVE Names: CVE-2009-3560 CVE-2009-3720CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequencesCVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequencesTwo buffer over-read flaws were found in the way Expat handled malformedUTF-8 sequences when processing XML files. A specially-crafted XML filecould cause applications using Expat to crash while parsing the file.(CVE-2009-3560, CVE-2009-3720)After installing the updated packages, applications using the Expat library must be restarted for the update to take effect.SL 3.0.x SRPMS:expat-1.95.5-6.2.src.rpm i386:expat-1.95.5-6.2.i386.rpmexpat-devel-1.95.5-6.2.i386.rpm x86_64:expat-1.95.5-6.2.i386.rpmexpat-1.95.5-6.2.x86_64.rpmexpat-devel-1.95.5-6.2.x86_64.rpmSL 4.x SRPMS:expat-1.95.7-4.el4_8.2.src.rpm i386:expat-1.95.7-4.el4_8.2.i386.rpmexpat-devel-1.95.7-4.el4_8.2.i386.rpm x86_64:expat-1.95.7-4.el4_8.2.i386.rpmexpat-1.95.7-4.el4_8.2.x86_64.rpmexpat-devel-1.95.7-4.el4_8.2.i386.rpmexpat-devel-1.95.7-4.el4_8.2.x86_64.rpmSL 5.x SRPMS:expat-1.95.8-8.3.el5_4.2.src.rpm i386:expat-1.95.8-8.3.el5_4.2.i386.rpmexpat-devel-1.95.8-8.3.el5_4.2.i386.rpm x86_64:expat-1.95.8-8.3.el5_4.2.i386.rpmexpat-1.95.8-8.3.el5_4.2.x86_64.rpmexpat-devel-1.95.8-8.3.el5_4.2.i386.rpmexpat-devel-1.95.8-8.3.el5_4.2.x86_64.rpm-Connie Sieh-Troy Dawson