Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 15.04: USN-2726-1 Critical Expat Denial Of Service Risk

ubuntu
Calendar Grey August 31, 2015
Scroller Ubuntu
Expat security flaws may lead to system failures or execution of unauthorized commands on Ubuntu platforms when processing specially crafted files.
Expat could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

Expat could be made to crash or run programs as your login if it opened a

specially crafted file.

Software Description:

- expat: XML parsing C library

Details:

It was discovered that Expat incorrectly handled malformed XML data. If a

user or application linked against Expat were tricked into opening a

crafted XML file, an attacker could cause a denial of service, or possibly

execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  lib64expat1                     2.1.0-6ubuntu1.1
  libexpat1                       2.1.0-6ubuntu1.1

Ubuntu 14.04 LTS:
  lib64expat1                     2.1.0-4ubuntu1.1
  libexpat1                       2.1.0-4ubuntu1.1

Ubuntu 12.04 LTS:
  lib64expat1                     2.0.1-7.2ubuntu1.2
  libexpat1                       2.0.1-7.2ubuntu1.2

After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.

References

https://ubuntu.com/security/notices/USN-2726-1

CVE-2015-1283

Severity
critical
Lowest
Low
Medium
High
Critical

August 31, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.