Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Ubuntu 16.04 LTS: USN-3010-1 Critical Expat Denial of Service Issue

Ubuntu Large Esm H500
Several security issues were fixed in Expat.
=========================================================================Ubuntu Security Notice USN-3010-1
June 20, 2016

expat vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Expat.

Software Description:
- expat: XML parsing C library

Details:

It was discovered that Expat unexpectedly called srand in certain
circumstances. This could reduce the security of calling applications.
(CVE-2012-6702)

It was discovered that Expat incorrectly handled seeding the random number
generator. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2016-5300)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  lib64expat1                     2.1.0-7ubuntu0.16.04.2
  libexpat1                       2.1.0-7ubuntu0.16.04.2

Ubuntu 15.10:
  lib64expat1                     2.1.0-7ubuntu0.15.10.2
  libexpat1                       2.1.0-7ubuntu0.15.10.2

Ubuntu 14.04 LTS:
  lib64expat1                     2.1.0-4ubuntu1.3
  libexpat1                       2.1.0-4ubuntu1.3

Ubuntu 12.04 LTS:
  lib64expat1                     2.0.1-7.2ubuntu1.4
  libexpat1                       2.0.1-7.2ubuntu1.4

After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3010-1
  CVE-2012-6702, CVE-2016-5300

Package Information:
  https://launchpad.net/ubuntu/+source/expat/2.1.0-7ubuntu0.16.04.2
  https://launchpad.net/ubuntu/+source/expat/2.1.0-7ubuntu0.15.10.2
  https://launchpad.net/ubuntu/+source/expat/2.1.0-4ubuntu1.3
  https://launchpad.net/ubuntu/+source/expat/2.0.1-7.2ubuntu1.4


Ubuntu 16.04 LTS: USN-3010-1 Critical Expat Denial of Service Issue

ubuntu
Calendar Grey June 20, 2016
Dist Ubuntu Esm H88
A recent security bulletin for Ubuntu addresses Expat vulnerabilities that impact the 16.04 LTS and prior versions, bolstering system security.
Several security issues were fixed in Expat.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: lib64expat1 2.1.0-7ubuntu0.16.04.2 libexpat1 2.1.0-7ubuntu0.16.04.2 Ubuntu 15.10: lib64expat1 2.1.0-7ubuntu0.15.10.2 libexpat1 2.1.0-7ubuntu0.15.10.2 Ubuntu 14.04 LTS: lib64expat1 2.1.0-4ubuntu1.3 libexpat1 2.1.0-4ubuntu1.3 Ubuntu 12.04 LTS: lib64expat1 2.0.1-7.2ubuntu1.4 libexpat1 2.0.1-7.2ubuntu1.4 After a standard system upgrade you need to restart any applications linked against Expat to effect the necessary changes.

References

https://ubuntu.com/security/notices/USN-3010-1

CVE-2012-6702, CVE-2016-5300

Severity
critical
Lowest
Low
Medium
High
Critical

June 20, 2016

Package Information

https://launchpad.net/ubuntu/+source/expat/2.1.0-7ubuntu0.16.04.2 https://launchpad.net/ubuntu/+source/expat/2.1.0-7ubuntu0.15.10.2 https://launchpad.net/ubuntu/+source/expat/2.1.0-4ubuntu1.3 https://launchpad.net/ubuntu/+source/expat/2.0.1-7.2ubuntu1.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here