Shang-Hung Wan discovered multiple vulnerabilities in the Expat XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5770-1
Rebase to 2.4.9. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-15ec504440 2022-10-07 15:54:31.083253 --------------------------------------------------------------------------------Name : expat Product : Fedora 36 Version : 2.4.9 Release : 1.fc36 URL : https://libexpat.github.io/ Summary : An XML parser library Description : This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. --------------------------------------------------------------------------------Update Information: Rebase to 2.4.9 --------------------------------------------------------------------------------ChangeLog: * Thu Sep 29 2022 Tomas Korbar - 2.4.9-1 - Rebase to 2.4.9 * Thu Jul 21 2022 Fedora Release Engineering - 2.4.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Fri Apr 8 2022 Tomas Korbar - 2.4.8-1 - Rebase to version 2.4.8 - Resolves: rhbz#2069454 --------------------------------------------------------------------------------References: [ 1 ] Bug #2130780 - CVE-2022-40674 expat: a use-after-free in the doContent function in xmlparse.c [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2130780 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-15ec504440' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-6834 https://linux.oracle.com/errata/ELSA-2022-6834.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: expat-2.1.0-15.0.1.el7_9.aarch64.rpm expat-devel-2.1.0-15.0.1.el7_9.aarch64.rpm expat-static-2.1.0-15.0.1.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/expat-2.1.0-15.0.1.el7_9.src.rpm Related CVEs: CVE-2022-40674 Description of changes: [2.1.0-15.0.1] - lib: Prevent integer overflow in doProlog [CVE-2022-23990][Orabug: 33910302] [2.1.0-15] - Ensure raw tagnames are safe exiting internalEntityParser - Resolves: CVE-2022-40674 _______________________________________________ El-errata mailing list
An update for expat is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: expat security update Advisory ID: RHSA-2022:5244-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:5244 Issue date: 2022-06-28 CVE Names: CVE-2022-25313 CVE-2022-25314 ==================================================================== 1. Summary: An update for expat is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: Expat is a C library for parsing XML documents. Security Fix(es): * expat: stack exhaustion in doctype parsing (CVE-2022-25313) * expat: integer overflow in copyString() (CVE-2022-25314) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, applications using the Expat library must be restarted for the update to take effect. 5. Bugsfixed (https://bugzilla.redhat.com/): 2056350 - CVE-2022-25313 expat: stack exhaustion in doctype parsing 2056354 - CVE-2022-25314 expat: integer overflow in copyString() 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): aarch64: expat-debuginfo-2.2.10-12.el9_0.2.aarch64.rpm expat-debugsource-2.2.10-12.el9_0.2.aarch64.rpm expat-devel-2.2.10-12.el9_0.2.aarch64.rpm ppc64le: expat-debuginfo-2.2.10-12.el9_0.2.ppc64le.rpm expat-debugsource-2.2.10-12.el9_0.2.ppc64le.rpm expat-devel-2.2.10-12.el9_0.2.ppc64le.rpm s390x: expat-debuginfo-2.2.10-12.el9_0.2.s390x.rpm expat-debugsource-2.2.10-12.el9_0.2.s390x.rpm expat-devel-2.2.10-12.el9_0.2.s390x.rpm x86_64: expat-debuginfo-2.2.10-12.el9_0.2.i686.rpm expat-debuginfo-2.2.10-12.el9_0.2.x86_64.rpm expat-debugsource-2.2.10-12.el9_0.2.i686.rpm expat-debugsource-2.2.10-12.el9_0.2.x86_64.rpm expat-devel-2.2.10-12.el9_0.2.i686.rpm expat-devel-2.2.10-12.el9_0.2.x86_64.rpm Red Hat Enterprise Linux BaseOS (v. 9): Source: expat-2.2.10-12.el9_0.2.src.rpm aarch64: expat-2.2.10-12.el9_0.2.aarch64.rpm expat-debuginfo-2.2.10-12.el9_0.2.aarch64.rpm expat-debugsource-2.2.10-12.el9_0.2.aarch64.rpm ppc64le: expat-2.2.10-12.el9_0.2.ppc64le.rpm expat-debuginfo-2.2.10-12.el9_0.2.ppc64le.rpm expat-debugsource-2.2.10-12.el9_0.2.ppc64le.rpm s390x: expat-2.2.10-12.el9_0.2.s390x.rpm expat-debuginfo-2.2.10-12.el9_0.2.s390x.rpm expat-debugsource-2.2.10-12.el9_0.2.s390x.rpm x86_64: expat-2.2.10-12.el9_0.2.i686.rpm expat-2.2.10-12.el9_0.2.x86_64.rpm expat-debuginfo-2.2.10-12.el9_0.2.i686.rpm expat-debuginfo-2.2.10-12.el9_0.2.x86_64.rpm expat-debugsource-2.2.10-12.el9_0.2.i686.rpm expat-debugsource-2.2.10-12.el9_0.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2022-25313 https://access.redhat.com/security/cve/CVE-2022-25314 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYr6V2tzjgjWX9erEAQhx2BAApcJi2EvcUkiTKbkRqHYQEu+aGBlMy0m0 FwD5XuL/DWKDz2EVTOTOlBsWzMpFijbpe8F/+Esi1airKxvG5fUNJ1kLxEnvAwxI ndZfHNjwURLNlrvYASazjCAwkxai4pI9M/YaUXRv4nRbjgsQWww0nbamsbRsGjUx PO+4DDTvFG8tu579I0OWSWUuq6q1l2keKGdIKH/q2PXeMZj4GUcsUP7grwtrMzGb PsWw9vAcaOls6ukllEoLgJHwYgHX+zxiG58S2x7UqwnEo7sK8F1YgEcAu3daWtDv duT3QpFHZzwL74ImfyPGnqxOFz0IeotLPZTdPyYA5uTqvXcvhnjVignyOER5x3Ll xvwQwjmEJ7rUX4TJS5irpEN98+Rz8CZRgUkTpjxuEGWpoAKNovHGGVaCdifPaeBF ZvqPDfSzaHPHDnvkpuNkiin3Xr0OznZRLMMQe8+H/YDax4oza+KTsyJ6//QvaDxA C2p6EApD4d1PFV7fMN5cX1VI1mHvTwBXqzjjrBIVkyQuDlqWzdc0Nu4LgfOysMEM ZfPUDWZeGc/uKuTbG8iKnfqQR1KMo2A0doOMPVcg7YWwe3y/uNBWrwmo6xYLwnug /3Uknknm+JWXEhcdKnim6NgkJSZ7qNl+iy9cyYPGLFYfr61DnsLsnf/MtMZa0BZn L4f1Gjmc9Io=jvNX -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for expat is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: expat security update Advisory ID: RHSA-2022:1070-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:1070 Issue date: 2022-03-28 CVE Names: CVE-2022-25235 CVE-2022-25236 CVE-2022-25315 ==================================================================== 1. Summary: An update for expat is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS EUS (v. 8.2) - aarch64, ppc64le, s390x, x86_64 3. Description: Expat is a C library for parsing XML documents. Security Fix(es): * expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235) * expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236) * expat: Integer overflow in storeRawNames() (CVE-2022-25315) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages,applications using the Expat library must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2056363 - CVE-2022-25315 expat: Integer overflow in storeRawNames() 2056366 - CVE-2022-25235 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution 2056370 - CVE-2022-25236 expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution 6. Package List: Red Hat Enterprise Linux BaseOS EUS (v. 8.2): Source: expat-2.2.5-3.el8_2.2.src.rpm aarch64: expat-2.2.5-3.el8_2.2.aarch64.rpm expat-debuginfo-2.2.5-3.el8_2.2.aarch64.rpm expat-debugsource-2.2.5-3.el8_2.2.aarch64.rpm expat-devel-2.2.5-3.el8_2.2.aarch64.rpm ppc64le: expat-2.2.5-3.el8_2.2.ppc64le.rpm expat-debuginfo-2.2.5-3.el8_2.2.ppc64le.rpm expat-debugsource-2.2.5-3.el8_2.2.ppc64le.rpm expat-devel-2.2.5-3.el8_2.2.ppc64le.rpm s390x: expat-2.2.5-3.el8_2.2.s390x.rpm expat-debuginfo-2.2.5-3.el8_2.2.s390x.rpm expat-debugsource-2.2.5-3.el8_2.2.s390x.rpm expat-devel-2.2.5-3.el8_2.2.s390x.rpm x86_64: expat-2.2.5-3.el8_2.2.i686.rpm expat-2.2.5-3.el8_2.2.x86_64.rpm expat-debuginfo-2.2.5-3.el8_2.2.i686.rpm expat-debuginfo-2.2.5-3.el8_2.2.x86_64.rpm expat-debugsource-2.2.5-3.el8_2.2.i686.rpm expat-debugsource-2.2.5-3.el8_2.2.x86_64.rpm expat-devel-2.2.5-3.el8_2.2.i686.rpm expat-devel-2.2.5-3.el8_2.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-25235 https://access.redhat.com/security/cve/CVE-2022-25236 https://access.redhat.com/security/cve/CVE-2022-25315 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYkHUeNzjgjWX9erEAQipxg//bKpjzpB7BURMCX/s3MwYmyXX50O6uAUG p1jOilzyzXA4xFvXa4OFO6uoWxfu5c480UDpFPe1QSaARLuw+HiVgcVo3k902UbP sapMWfYJgULEGjKlwlOTMY+re4kEUEKCn8UfwoXOXJgwbi5AgbR3szqyWGA6EP7N d5qk1KLY8aS9F10bt9N4E5SECcCCniAJQ1zPaLrkKAk0JV5X/gLZOv8mNmfHqstn pfLdCeoan+sPr2q9k+166WT4kZVyxadcN7zrTWGvluxsUcPwyoug21OCkHa8kA91 +O6IxQwJg7YCG7hLl02GSrLWxmcYwaZDuMIC+GD1AYq4IKcPWyQJ7UzSX3zpHPph 10Crrs92zVwOt5Y0pBfaFLNh6TJWCQdgbTSAepluo9q9AshGw5t4aA6sk7bHrzQr wX3+Ka0AoHhsyaDsgwt2YJurgNSDVO/xpXjAjw8XTEV0vW8caEs2fZYsejl8/QAc 1/LNDy6axRQeXGCtg38pwCTxNmldTvWsGUUhkSshZRRtN7a5CnDv6iORJHUWwIS2 +QiUOFuEgg7ZzqQVGIirflBIo3exDZz3vDdHoMs2x4DgpewdZaOLg21i/8wstsuc MbErEP/Bwlx1MqQTocTq/dc2iTSTFE6G/Sfb8zxCRgubfD+e45t0nRrun1532NnX nSqxYuwuaoo=Hb0e -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Rebase to version 2.4.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-07ff33f237 2022-03-18 19:12:07.464988 --------------------------------------------------------------------------------Name : expat Product : Fedora 34 Version : 2.4.6 Release : 1.fc34 URL : https://libexpat.github.io/ Summary : An XML parser library Description : This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. --------------------------------------------------------------------------------Update Information: Rebase to version 2.4.6 --------------------------------------------------------------------------------ChangeLog: * Mon Feb 21 2022 Tomas Korbar - 2.4.6-1 - Rebase to version 2.4.6 - Resolves: rhbz#2056133 --------------------------------------------------------------------------------References: [ 1 ] Bug #2056133 - expat-2.4.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2056133 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-07ff33f237' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Switched to using system expat library. Updated expat packages are needed to fully resolve this flaw.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10949 2009-11-04 10:55:26 -------------------------------------------------------------------------------- Name : PyXML Product : Fedora 10 Version : 0.8.4 Release : 12.fc10 URL : Summary : XML libraries for python. Description : An XML package for Python. The distribution contains a validating XML parser, an implementation of the SAX and DOM programming interfaces and an interface to the Expat parser. -------------------------------------------------------------------------------- Update Information: Switched to using system expat library. Updated expat packages are needed to fully resolve this flaw. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 2 2009 Roman Rakus - 0.8.4-12 - Use system expat library * Fri Oct 30 2009 Roman Rakus - 0.8.4-11 - Fix buffer over read -------------------------------------------------------------------------------- References: [ 1 ] Bug #531697 - CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences https://bugzilla.redhat.com/show_bug.cgi?id=531697 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update PyXML' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailinglist
Switched to using system expat library. Updated expat packages are needed to fully resolve this flaw.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-11030 2009-11-04 10:57:28.710919 -------------------------------------------------------------------------------- Name : PyXML Product : Fedora 11 Version : 0.8.4 Release : 16.fc11 URL : Summary : XML libraries for python Description : An XML package for Python. The distribution contains a validating XML parser, an implementation of the SAX and DOM programming interfaces and an interface to the Expat parser. -------------------------------------------------------------------------------- Update Information: Switched to using system expat library. Updated expat packages are needed to fully resolve this flaw. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 2 2009 Roman Rakus - 0.8.4-16 - Use system expat library * Fri Oct 30 2009 Roman Rakus - 0.8.4-15 - Fix buffer over read -------------------------------------------------------------------------------- References: [ 1 ] Bug #531697 - CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences https://bugzilla.redhat.com/show_bug.cgi?id=531697 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update PyXML' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.