[CLSA-2024:1726163048] expat: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2024-09-12 17:44:11 UTC
Description:
- The release version was raised because it corresponds to version 13 - CVE-2024-45490: reject negative len for XML_ParseBuffer to prevent improper restriction of XML External Entity Reference - CVE-2024-45491: prevent integer overflow in dtdCopy - CVE-2024-45492: prevent integer overflow in nextScaffoldPart
Updated packages:
  • expat-2.2.5-13.el8.tuxcare.els1.i686.rpm
    sha:dde97e6a2ae2fdfef6796514871bfd03eea3e629f8d62dbf6e54e7649111875b
  • expat-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:e5ea36e46054d9670716151489bd5844a2dcd5ceaf62fa1286235bd31427c6cc
  • expat-devel-2.2.5-13.el8.tuxcare.els1.i686.rpm
    sha:13dee796bdf74db6a6e9700f39a0be13a325f4d8d2b493dc9c901611aed5a59f
  • expat-devel-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:85e427c6c82ddb77f7ecbfdb1dfa1b706cc47980fe80ed33076312749e5a3977
  • expat-static-2.2.5-13.el8.tuxcare.els1.x86_64.rpm
    sha:3cb2161f0187e65ac404f89a3041c53db9bd51926232aaa8b0333cc9af2351c3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.