[CLSA-2022:1667412749] Fix CVE(s): CVE-2022-43680
Type:
security
Severity:
None
Release date:
2022-11-02 18:12:29 UTC
Description:
* SECURITY UPDATE: Fix overeager DTD destruction - debian/patches/CVE-2022-43680: Fix heap use-after-free after overeager destruction of a shared DTD in function XML_ExternalEntityParserCreate in out-of-memory situations - CVE-2022-43680
Updated packages:
  • expat_2.1.0-7ubuntu0.16.04.5+tuxcare.els3_amd64.deb
    sha:1710c697eb6e83cb9cfed37ef4e7cb97584d534f
  • libexpat1_2.1.0-7ubuntu0.16.04.5+tuxcare.els3_amd64.deb
    sha:a7d027ab2e203d03ef0a8e20e44a6df43d9911c4
  • libexpat1-dev_2.1.0-7ubuntu0.16.04.5+tuxcare.els3_amd64.deb
    sha:0afab4787cd146a4d85ec16b196b13365f0eb8bc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.