[CLSA-2024:1726163202] expat: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2024-09-12 17:46:46 UTC
Description:
- The release version was raised because it corresponds to version 13 - CVE-2024-45490: reject negative len for XML_ParseBuffer to prevent improper restriction of XML External Entity Reference - CVE-2024-45491: prevent integer overflow in dtdCopy - CVE-2024-45492: prevent integer overflow in nextScaffoldPart
Updated packages:
  • expat-2.2.5-13.el8.tuxcare.els1.i686.rpm
    sha:ef404750a3beb011779cc9e59c646193cc66c440fd689d5fb54c0aafa3451bb8
  • expat-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:7e361d2b7c99ee1376f4a3ea9dfb5697100f446e4d11d368efa353cfef9d013e
  • expat-devel-2.2.5-13.el8.tuxcare.els1.i686.rpm
    sha:7854c72b61c9e26e2a1e40280ad95f8fde84e9965527edbf26b9014df8bb4e0e
  • expat-devel-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:1c227dee7f689fccda3e3e31ee5a4e2fd1ce65307b8b9f9dbf498d4665e1a269
  • expat-static-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:7ae9534c36409dbe3ea9b8463404807a2946bd2bb0fa088fd454a3b72da664e1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.