The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1530 https://linux.oracle.com/errata/ELSA-2024-1530.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: expat-2.5.0-1.el9_3.1.i686.rpm expat-2.5.0-1.el9_3.1.x86_64.rpm expat-devel-2.5.0-1.el9_3.1.i686.rpm expat-devel-2.5.0-1.el9_3.1.x86_64.rpm aarch64: expat-2.5.0-1.el9_3.1.aarch64.rpm expat-devel-2.5.0-1.el9_3.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//expat-2.5.0-1.el9_3.1.src.rpm Related CVEs: CVE-2023-52425 CVE-2024-28757 Description of changes: [2.5.0-1.1] - CVE-2023-52425: Fix parsing of large tokens - CVE-2024-28757: Reject direct parameter entity recursion - Resolves: RHEL-29698 - Resolves: RHEL-29695 _______________________________________________ El-errata mailing list
CVE-2017-16931 parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the . Hash: SHA512 Package : libxml2 Version : 2.8.0+dfsg1-7+wheezy11 CVE ID : CVE-2017-16931 CVE-2017-16932 CVE-2017-16931 parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name. CVE-2017-16932 parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities. For Debian 7 "Wheezy", these problems have been fixed in version 2.8.0+dfsg1-7+wheezy11. We recommend that you upgrade your libxml2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Essential security patches for libxml2 have been released to fix vulnerabilities related to parameter-entity management. An upgrade is advised for Debian 7 users.. Debian Security, libxml2 Update, Parameter-Entity Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.