Improper restriction of xml entity expansion depth in libexpat. (CVE-2024-8176) References: - https://bugs.mageia.org/show_bug.cgi?id=34111 . MGASA-2025-0109 - Updated expat packages fix security vulnerability Publication date: 22 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0109.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-8176 Improper restriction of xml entity expansion depth in libexpat. (CVE-2024-8176) References: - https://bugs.mageia.org/show_bug.cgi?id=34111 - https://www.openwall.com/lists/oss-security/2025/03/14/5 - https://www.cve.org/CVERecord?id=CVE-2024-8176 SRPMS: - 9/core/expat-2.7.0-1.mga9 . Updated expat packages address security flaws in XML processing for Mageia 9. Strongly recommended patches available now.. improper, restriction, entity, expansion, depth, libexpat, (cve-2024-8176), https. . Severity: Critical. LinuxSecurity.com Team
It was discovered that there was a XML external entity vulnerability in the lemonldap-ng single-sign on system. This may have led to the disclosure of confidential data, denial of service, server side request forgery, port scanning, etc. . Package : lemonldap-ng Version : 1.3.3-1+deb8u2 CVE ID : CVE-2019-13031 Debian Bug : #931117 It was discovered that there was a XML external entity vulnerability in the lemonldap-ng single-sign on system. This may have led to the disclosure of confidential data, denial of service, server side request forgery, port scanning, etc. For Debian 8 "Jessie", this issue has been fixed in lemonldap-ng version 1.3.3-1+deb8u2. We recommend that you upgrade your lemonldap-ng packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.