Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 16.04 LTS: USN-3010-1 Critical Expat Denial of Service Issue

ubuntu
Calendar Grey June 20, 2016
Scroller Ubuntu
A recent security bulletin for Ubuntu addresses Expat vulnerabilities that impact the 16.04 LTS and prior versions, bolstering system security.
Several security issues were fixed in Expat.

Summary

Several security issues were fixed in Expat.

Software Description:

- expat: XML parsing C library

Details:

It was discovered that Expat unexpectedly called srand in certain

circumstances. This could reduce the security of calling applications.

(CVE-2012-6702)

It was discovered that Expat incorrectly handled seeding the random number

generator. A remote attacker could possibly use this issue to cause a

denial of service. (CVE-2016-5300)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  lib64expat1                     2.1.0-7ubuntu0.16.04.2
  libexpat1                       2.1.0-7ubuntu0.16.04.2

Ubuntu 15.10:
  lib64expat1                     2.1.0-7ubuntu0.15.10.2
  libexpat1                       2.1.0-7ubuntu0.15.10.2

Ubuntu 14.04 LTS:
  lib64expat1                     2.1.0-4ubuntu1.3
  libexpat1                       2.1.0-4ubuntu1.3

Ubuntu 12.04 LTS:
  lib64expat1                     2.0.1-7.2ubuntu1.4
  libexpat1                       2.0.1-7.2ubuntu1.4

After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.

References

https://ubuntu.com/security/notices/USN-3010-1

CVE-2012-6702, CVE-2016-5300

Severity
critical
Lowest
Low
Medium
High
Critical

June 20, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.