Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Slackware: 2022-263-01 Critical: Expat Denial Of Service Attack

slackware
Calendar Grey September 20, 2022
Dist Slackware Esm H88
Improve your Slackware environment by installing the newest expat updates to resolve a critical vulnerability.
New expat packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/expat-2.4.9-i586-1_slack15.0.txz: Upgraded. This update fixes a security issue: Heap use-after-free vulnerability in function doContent. Expected impact is denial of service or potentially arbitrary code execution. For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-40674 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab () for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware 15.0:
Updated package for Slackware x86_64 15.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 14.0 package: 8875d0a7ef12b8b874e0c7a8f3daec23 expat-2.4.3-i486-7_slack14.0.txz
Slackware x86_64 14.0 package: 54c5c55709bf30f4f1c25b058e0e9dc0 expat-2.4.3-x86_64-7_slack14.0.txz
Slackware 14.1 package: 415fb2239e9bf331a113fa5a969f54f6 expat-2.4.3-i486-7_slack14.1.txz
Slackware x86_64 14.1 package: 7d2cddd0b8f59955c015fd816b27f1cf expat-2.4.3-x86_64-7_slack14.1.txz
Slackware 14.2 package: afefed8cbde7f834e8ce26bed09942b3 expat-2.4.3-i586-7_slack14.2.txz
Slackware x86_64 14.2 package: b4275c9656969751a44d04babbbffdbd expat-2.4.3-x86_64-7_slack14.2.txz
Slackware 15.0 package: 3e20a4c46f535008c74bafa0c6e0ce4b expat-2.4.9-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: f92b2727f730ace64518e86f62540b74 expat-2.4.9-x86_64-1_slack15.0.txz
Slackware -current package: 61b854ca80084f8d10756696c385108c l/expat-2.4.9-i586-1.txz
Slackware x86_64 -current package: 4367548913891639223cdccf9fac2827 l/expat-2.4.9-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg expat-2.4.9-i586-1_slack15.0.txz

Related News

Your message here