[CLSA-2024:1726163032] expat: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2024-09-12 17:43:54 UTC
Description:
- The release version was raised because it corresponds to version 13 - CVE-2024-45490: reject negative len for XML_ParseBuffer to prevent improper restriction of XML External Entity Reference - CVE-2024-45491: prevent integer overflow in dtdCopy - CVE-2024-45492: prevent integer overflow in nextScaffoldPart
Updated packages:
  • expat-2.2.5-13.el8.tuxcare.els1.i686.rpm
    sha:15cd8e12b242f932948699ccc20b1e1b2af04079b50713f5a5f0b84fdce27ff8
  • expat-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:0954884070c06491d26db9eea622abef10a75d841f092eb7efd25706101884e0
  • expat-devel-2.2.5-13.el8.tuxcare.els1.i686.rpm
    sha:f6e78ca5c66d9fad7e2c22f7a1a5ef97af390b91268452a2b66cc598ecd7ad82
  • expat-devel-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:01c85943adadeecf99c20a3acabb84d59491789bfd1727fb057518a26da55cd7
  • expat-static-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:ec38e79bfc165cd56874fc9735f10110b2c620f9878f6037480246c4260faf7c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.