Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian: Urgent Advisory 2022-2457-01 Regarding Expat Memory Leak Issue

slackware
Calendar Grey October 25, 2022
Dist Slackware Esm H88
Latest expat updates for Slackware 14.0-15.0 tackle critical vulnerabilities. Update promptly to mitigate any possible threats.
New expat packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/expat-2.5.0-i586-1_slack15.0.txz: Upgraded. This update fixes a security issue: Fix heap use-after-free after overeager destruction of a shared DTD in function XML_ExternalEntityParserCreate in out-of-memory situations. Expected impact is denial of service or potentially arbitrary code execution. For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-43680 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/expat-2.4.3-i486-8_slack14.0.txz
Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/expat-2.4.3-x86_64-8_slack14.0.txz
Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/expat-2.4.3-i486-8_slack14.1.txz
Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/expat-2.4.3-x86_64-8_slack14.1.txz
Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/expat-2.4.3-i586-8_slack14.2.txz
Updated package for Slackware x86_64...

Read the Full Advisory

MD5 Signatures

Slackware 14.0 package: 0fd2ba3c6f0c27f4fd9d68ae5a5dc73a expat-2.4.3-i486-8_slack14.0.txz
Slackware x86_64 14.0 package: c9c50bb9d09921396dc8cba832ca6c54 expat-2.4.3-x86_64-8_slack14.0.txz
Slackware 14.1 package: a3abb5b8416e865627d865c072c4a8c6 expat-2.4.3-i486-8_slack14.1.txz
Slackware x86_64 14.1 package: 3bceb11fb5b69049cb3a121fd879e749 expat-2.4.3-x86_64-8_slack14.1.txz
Slackware 14.2 package: 6c13bb9d0198679b67f19d702179f331 expat-2.4.3-i586-8_slack14.2.txz
Slackware x86_64 14.2 package: 71ba3c391725745344ccb950a207a2e3 expat-2.4.3-x86_64-8_slack14.2.txz
Slackware 15.0 package: 13d8322d1d270c480ca10a01f47585b1 expat-2.5.0-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: 126b299851d0be6f583045a04a8ecf41 expat-2.5.0-x86_64-1_slack15.0.txz
Slackware -current package: cb21f24eb0e34d1b4d9882976a577fae l/expat-2.5.0-i586-1.txz
Slackware x86_64 -current package: bb90f8668aef64c82c24d3f57b15f6e4 l/expat-2.5.0-x86_64-1.txz

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg expat-2.5.0-i586-1_slack15.0.txz

Related News

Your message here