Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Ubuntu 21.10: USN-5288-1 Critical Expat Issues Resolved

Ubuntu Large Esm H500
Several security issues were fixed in Expat.
=========================================================================Ubuntu Security Notice USN-5288-1
February 21, 2022

expat vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in Expat.

Software Description:
- expat: XML parsing C library

Details:

It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.10:
  libexpat1                       2.4.1-2ubuntu0.1

Ubuntu 20.04 LTS:
  libexpat1                       2.2.9-1ubuntu0.2

Ubuntu 18.04 LTS:
  libexpat1                       2.2.5-3ubuntu0.4

Ubuntu 16.04 ESM:
  lib64expat1                     2.1.0-7ubuntu0.16.04.5+esm2
  libexpat1                       2.1.0-7ubuntu0.16.04.5+esm2

Ubuntu 14.04 ESM:
  lib64expat1                     2.1.0-4ubuntu1.4+esm4
  libexpat1                       2.1.0-4ubuntu1.4+esm4

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5288-1
  CVE-2021-45960, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823,
  CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827,
  CVE-2022-23852, CVE-2022-23990, CVE-2022-25235, CVE-2022-25236

Package Information:
  https://launchpad.net/ubuntu/+source/expat/2.4.1-2ubuntu0.1
  https://launchpad.net/ubuntu/+source/expat/2.2.9-1ubuntu0.2
  https://launchpad.net/ubuntu/+source/expat/2.2.5-3ubuntu0.4

Ubuntu 21.10: USN-5288-1 Critical Expat Issues Resolved

ubuntu
Calendar Grey February 21, 2022
Dist Ubuntu Esm H88
Measures to address severe Expat flaws across various Ubuntu releases disclosed in USN-5288-1. Take swift action to protect your environments.
Several security issues were fixed in Expat.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: libexpat1 2.4.1-2ubuntu0.1 Ubuntu 20.04 LTS: libexpat1 2.2.9-1ubuntu0.2 Ubuntu 18.04 LTS: libexpat1 2.2.5-3ubuntu0.4 Ubuntu 16.04 ESM: lib64expat1 2.1.0-7ubuntu0.16.04.5+esm2 libexpat1 2.1.0-7ubuntu0.16.04.5+esm2 Ubuntu 14.04 ESM: lib64expat1 2.1.0-4ubuntu1.4+esm4 libexpat1 2.1.0-4ubuntu1.4+esm4 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5288-1

CVE-2021-45960, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823,

CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827,

CVE-2022-23852, CVE-2022-23990, CVE-2022-25235, CVE-2022-25236

Severity
critical
Lowest
Low
Medium
High
Critical

February 21, 2022

Package Information

https://launchpad.net/ubuntu/+source/expat/2.4.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/expat/2.2.9-1ubuntu0.2 https://launchpad.net/ubuntu/+source/expat/2.2.5-3ubuntu0.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here