Patch for CVE-2019-15531. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-b467cab3c8 2019-09-30 00:00:36.231186 --------------------------------------------------------------------------------Name : libextractor Product : Fedora 31 Version : 1.9 Release : 5.fc31 URL : Summary : Simple library for keyword extraction Description : libextractor is a simple library for keyword extraction. libextractor does not support all formats but supports a simple plugging mechanism such that you can quickly add extractors for additional formats, even without recompiling libextractor. libextractor typically ships with a dozen helper-libraries that can be used to obtain keywords from common file-types. libextractor is a part of the GNU project (). --------------------------------------------------------------------------------Update Information: Patch for CVE-2019-15531 --------------------------------------------------------------------------------References: [ 1 ] Bug #1749219 - CVE-2019-15531 libextractor: heap-based buffer over-read in function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1749219 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-b467cab3c8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that there was a heap-based buffer overread vulnerability in expat, an XML parsing library. A specially-crafted XML input could fool the parser into changing . Package : expat Version : 2.1.0-6+deb8u6 CVE IDs : CVE-2019-15903 Debian Bug : #939394 It was discovered that there was a heap-based buffer overread vulnerability in expat, an XML parsing library. A specially-crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer overread. For Debian 8 "Jessie", this issue has been fixed in expat version 2.1.0-6+deb8u6. We recommend that you upgrade your expat packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.