Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Slackware 15.0: SSA:2024-312-01 critical: expat buffer overflow

slackware
Calendar Grey November 7, 2024
Dist Slackware Esm H88
Latest expat distributions for Slackware address significant vulnerabilities, decreasing the risk of system failures and bolstering overall security measures.
New expat packages are available for Slackware 15.0 and -current to fix security issues

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/expat-2.6.4-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and a security issue: Fix crash within function XML_ResumeParser from a NULL pointer dereference by disallowing function XML_StopParser to (stop or) suspend an unstarted parser. A new error code XML_ERROR_NOT_STARTED was introduced to properly communicate this situation. For more information, see: https://www.cve.org/CVERecord?id=CVE-2024-50602 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/expat-2.6.4-i586-1_slack15.0.txz
Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/expat-2.6.4-x86_64-1_slack15.0.txz
Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/expat-2.6.4-i686-1.txz
Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/expat-2.6.4-x86_64-1.txz

MD5 Signatures

Slackware 15.0 package: 1e15fcdecc94a63e6fd40bbf8cdc5fb3 expat-2.6.4-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: 772024f06adb89d3312149c9262dc990 expat-2.6.4-x86_64-1_slack15.0.txz
Slackware -current package: aa74cc58543b3195a6651d31f3e51db5 l/expat-2.6.4-i686-1.txz
Slackware x86_64 -current package: bf218e0984fb9188f246afe67c6e664e l/expat-2.6.4-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg expat-2.6.4-i586-1_slack15.0.txz

Your message here