[CLSA-2022:1660759632] Fixed 13 CVEs in expat
Type:
security
Severity:
Critical
Release date:
2022-08-17
Description:
- CVE-2022-25236: Fix insertion of namespace-separator characters into namespace URIs - CVE-2022-25235: Fix malformed UTF-8 sequences which can lead to arbitrary code execution - CVE-2022-25315: Fix integer overflow in storeRawNames() - CVE-2022-22822: Fix integer overflow in addBinding() - CVE-2022-22823: Fix integer overflow in build_model() - CVE-2022-22824: Fix integer overflow in defineAttribute() - CVE-2022-22825: Fix integer overflow in lookup() - CVE-2022-22826: Fix integer overflow in nextScaffoldPart() - CVE-2022-22827: Fix integer overflow in storeAtts() - CVE-2022-23852: Fix integer overflow in XML_GetBuffer() - CVE-2021-46143: Fix integer overflow on m_groupSize in doProlog() - CVE-2021-45960: Fix troublesome left shifts in storeAtts() - CVE-2022-23990: Fix integer overflow in doProlog()
Updated packages:
  • expat-devel-2.0.1-13.el6_8.tuxcare.els1.x86_64.rpm
    sha:02c92a67031790b94ffe1c87f68c24141b3bc948
  • expat-2.0.1-13.el6_8.tuxcare.els1.x86_64.rpm
    sha:9cdefb9fe388783ea99f8cf05f8e1b3e11a4b8c9
  • expat-2.0.1-13.el6_8.tuxcare.els1.i686.rpm
    sha:3a282d0b6febb6eb7d8167c529fced61716ad8d8
  • expat-devel-2.0.1-13.el6_8.tuxcare.els1.i686.rpm
    sha:b612b76f4d644660bcfe7c215d4dd62b4b6c52c3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.