expat 2.4.1-2ubuntu0.3 source package in Ubuntu
Changelog
expat (2.4.1-2ubuntu0.3) impish-security; urgency=medium
* SECURITY UPDATE: Stack exhaustion
- debian/patches/CVE-2022-25313.patch: prevent
stack exhaustion in build_model in expat/lib/xmlparse.c.
- debian/patches/fix-build_model-regression.patch: fix build_model
regression in expat/lib/xmlparse.c.
- debian/patches/protect-against-nested-element*: in expat/lib/xmlparse.
- CVE-2022-25313
* SECURITY UPDATE: Integer overflow
- debian/patches/CVE-2022-25314.patch: prevent integer overflow in
copyString in expat/lib/xmlparse.c.
- CVE-2022-25314
* SECURITY UPDATE: Integer overflow
- debian/patches/CVE-2022-25315.patch: prevent integer overflow in
storeRawNames in expat/lib/xmlparse.c.
- CVE-2022-25315
* SECURITY UPDATE: relax fix to CVE-2022-25236 with regard to
RFC 3986 URI characters and possibly regressions
- debian/patches/CVE-2022-25236-3.patch: add a note on namespace URI
validation in expat/doc/reference.html, expat/lib/expat.h.
- debian/patches/CVE-2022-25236-4.patch: document namespace separator
effect right in header expat/lib/expat.h.
- debian/patches/CVE-2022-25236-5.patch: cover relaxed fix in tests.
- debian/patches/CVE-2022-25236-6.patch: relax fix with regard to
RFC 3986 URI characters in expat/lib/xmlparse.c. (LP: #1963903)
-- Leonidas Da Silva Barbosa <email address hidden> Mon, 21 Feb 2022 14:42:01 -0300
Upload details
- Uploaded by:
- Leonidas S. Barbosa
- Uploaded to:
- Impish
- Original maintainer:
- Ubuntu Developers
- Architectures:
- any
- Section:
- text
- Urgency:
- Medium Urgency
See full publishing history Publishing
| Series | Published | Component | Section |
|---|
Downloads
| File | Size | SHA-256 Checksum |
|---|---|---|
| expat_2.4.1.orig.tar.gz | 7.9 MiB | 660e5852b26125f4508183dfa134e18eb33a892dbd8e06786ea38d92dbbb5b07 |
| expat_2.4.1-2ubuntu0.3.debian.tar.xz | 25.5 KiB | e07a6ef5af5b6191b435b59c61faef60cca34ea979dba0c875abcd0ce5106ea2 |
| expat_2.4.1-2ubuntu0.3.dsc | 2.0 KiB | 1f824b0e0efcb3cff36f276e0ac101e7dd3279fb9d9436fec20a1191feda5d2f |
Available diffs
Binary packages built by this source
- expat: No summary available for expat in ubuntu impish.
No description available for expat in ubuntu impish.
- expat-dbgsym: No summary available for expat-dbgsym in ubuntu impish.
No description available for expat-dbgsym in ubuntu impish.
- libexpat1: No summary available for libexpat1 in ubuntu impish.
No description available for libexpat1 in ubuntu impish.
- libexpat1-dbgsym: No summary available for libexpat1-dbgsym in ubuntu impish.
No description available for libexpat1-dbgsym in ubuntu impish.
- libexpat1-dev: No summary available for libexpat1-dev in ubuntu impish.
No description available for libexpat1-dev in ubuntu impish.
