Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in Expat (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in Expat (Aktualisierung)
ID: USN-5638-3
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 16.04 ESM, Ubuntu 22.04 LTS, Ubuntu 22.10
Datum: Mi, 23. November 2022, 23:30
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43680
https://launchpad.net/ubuntu/+source/expat/2.4.8-2ubuntu0.22.10.1
Applikationen: expat
Update von: Ausführen beliebiger Kommandos in Expat

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============7535388174410051205==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="------------hhfiFJ509NhWk10fJ1q8vqU6"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------hhfiFJ509NhWk10fJ1q8vqU6
Content-Type: multipart/mixed;
boundary="------------YniB4KCgR1gLpfKE9IhXHP48";
protected-headers="v1"
From: David Fernandez Gonzalez <david.fernandezgonzalez@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <86c5dd3d-8a49-1b12-665d-f1e069a71dd8@canonical.com>
Subject: [USN-5638-3] Expat vulnerability

--------------YniB4KCgR1gLpfKE9IhXHP48
Content-Type: multipart/mixed;
boundary="------------stx90b0AkEiL0PVX74Tu4ash"

--------------stx90b0AkEiL0PVX74Tu4ash
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: base64

==========================================================================
Ubuntu Security Notice USN-5638-3
November 23, 2022

expat vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM

Summary:

Expat could be made to crash or execute arbitrary code.

Software Description:
- expat: XML parsing C library

Details:

USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-43680)
This update also fixes a minor regression introduced in
Ubuntu 18.04 LTS.

We apologize for the inconvenience.

Original advisory details:

 Rhodri James discovered that Expat incorrectly handled memory when
 processing certain malformed XML files. An attacker could possibly
 use this issue to cause a crash or execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
  expat                           2.4.8-2ubuntu0.22.10.1
  libexpat1                       2.4.8-2ubuntu0.22.10.1

Ubuntu 22.04 LTS:
  expat                           2.4.7-1ubuntu0.2
  libexpat1                       2.4.7-1ubuntu0.2

Ubuntu 20.04 LTS:
  expat                           2.2.9-1ubuntu0.6
  libexpat1                       2.2.9-1ubuntu0.6

Ubuntu 18.04 LTS:
  expat                           2.2.5-3ubuntu0.9
  libexpat1                       2.2.5-3ubuntu0.9

Ubuntu 16.04 ESM:
  expat                           2.1.0-7ubuntu0.16.04.5+esm7
  lib64expat1                     2.1.0-7ubuntu0.16.04.5+esm7
  libexpat1                       2.1.0-7ubuntu0.16.04.5+esm7

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5638-3
  https://ubuntu.com/security/notices/USN-5638-1
  CVE-2022-43680

Package Information:
https://launchpad.net/ubuntu/+source/expat/2.4.8-2ubuntu0.22.10.1
  https://launchpad.net/ubuntu/+source/expat/2.4.7-1ubuntu0.2
  https://launchpad.net/ubuntu/+source/expat/2.2.9-1ubuntu0.6
  https://launchpad.net/ubuntu/+source/expat/2.2.5-3ubuntu0.9

--------------stx90b0AkEiL0PVX74Tu4ash
Content-Type: application/pgp-keys;
name="OpenPGP_0x86A73CCF854ECB9A.asc"
Content-Disposition: attachment;
filename="OpenPGP_0x86A73CCF854ECB9A.asc"
Content-Description: OpenPGP public key
Content-Transfer-Encoding: quoted-printable

-----BEGIN PGP PUBLIC KEY BLOCK-----

xsFNBGM0XCwBEAC/1sgU6QaxKU49T3i2BdLteX5GqAJfpwzSr2RBvr6L8W//AoUn
gP8z1eiDwutJ62pTf473COZoDXTgdi7R0zT0QCbCZoHo4hVR2VHnfmxOR94XCVSE
1rvO3HF5NVLGVJl2V465y2sz2L2IWTYu1xvY/4FPhtWXLwHJmojmDbuRHF2AmX8A
6ECxYuZAcadLOuQO8mQV95YgVoWmoAjJKb1audHcLA4MRglds7jr9GgYkYWQ38Gk
AM9R6DNEbRowxMBCwkj3jVz8r0kO1WOPWP0in1VvGMrlcSIgjaxW/re427CSB2LA
9QwFc+EmOE5PoNWCoAuPa+vhoo7xqTY2Qr2Wvu86PlpWS596RWFzmz5UVan5yhaB
qEoEsZc7ZQbS4Qwc7x4teKhk8xQjx6lRsO6g1b4Wlm6S0PcELo1J5zwC+16MSZff
eK3zuAdijyNwL2xl8XwShTUxFo/mpyB+W+zDUU8OBudsYwKYSWUbMZzferYlndcv
3atN6ZteWmuPtxHIGkkc5yChs1dsQ1ke1e9sUQA0UCdMVL4awA/LGSlo9ymTvL3Z
Qwh05ujgDs09p7AkUFLLDhgS437yxzT46RqYcurDMn27kwTcfd4s2FJZVV90+Dgr
z4o6lAjObZXVTsE+E2eLIxlXpfH2g3Nr/1Ipe9VZ5FetTgu32Bd3iRUQ2wARAQAB
zUBEYXZpZCBGZXJuYW5kZXogR29uemFsZXogPGRhdmlkLmZlcm5hbmRlemdvbnph
bGV6QGNhbm9uaWNhbC5jb20+wsGUBBMBCgA+FiEEZj5eir1e7OtcLCXYhqc8z4VO
y5oFAmM0XCwCGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQhqc8
z4VOy5oojA/+MNrpuhfKM5Gm5h9cKMDUysMFfULChDjzQZdkM6Gh9xBFYyidoOq2
jOAs0xEk9vb6WfB+enfxFF1jmSXPISBvdHzoI4NpAoF+tf+e2tuC6TA+hLH/VqK8
yGy9SzChihpBLze6/S3dct6ayPew2lGC+r6gUMs8XiZyTMACoZR4ywt3BolWDGpp
6za7ylFUcJOTecqVRLVDKu5+8JrXSeG/jv1QqYR1ltHdAQVxkvctOVJciOcyIz45
XJkrjFJB/kMNE6sOq2z7lMKIauFZCTaLUVrq0brY4IHtXvsa/2vN6h9bWPFor3KU
hVIDhuEdjS4g3ge57+sCYrPGOHXRk+mJrqSd9T1bgLxXOP65kRUhecIRxfTovMTm
iifFcAY2Q/iEAn0SMCycmi9SZngaUd+IxYXk0tCfH2Y0q12vMuuuox94+A0t05Vr
0Vej0NiBebB01a90tcJBbIVV09NrOYXDhyDvUCsuineao+CNXKoM3SaNFjOiwZgz
yR1t2LcBlGVAQq/gySTE8X4WVIwVknUxcIUcOSzGDMEtd4X0qFv6A0oib/VEzuOz
JVE4WqiRCXKRws5j3KMHrNi4Inac/Ew0ph60NctY50xGxQqrHhxIZG9FKb1hM+Ov
cX2dy1HrLJwHf4le+Y4Yeobts8alQvJKd9IaVYZcKSt/M0JolPIPKdTOwU0EYzRc
LAEQANVn81wr2CkEdUQ0l8A5gN3NOft4P6TBQBvxK+9QW9n1l/JT7Pfa1lvE62xx
s+LIceFExzcq1Dfd9qnNBc39qY2XwIwNx7Gz67libTikfYhBO1gtfZ/i8GJuDjLH
xOAEBnDVogkE+lnBxfZ0adfldzJ3wKMQUU7LP6+dAmF91hyJO1HOQ5eOntWhbzqW
R69kRqlN7Wwd++7TbgqgiPtw6Vreu1BLlovkcImA6TZyJeD5SBN0eApBjWNZ5QCj
wd0hTeCUWCu2USBApZQn76ORTIpZ4j573DVvQZq88WsN875Yu2U2pHBQtEYFT8WG
Lrk5aNqDeQGw4jxGVvXwJjPOviGhhrzditvUD2L23fh7cTWSQJ6BZHoymLYQk3YZ
C19ewaoNsVt1a5WxomZdPspkJLaMyiXVT0tqtcyFDb6ekEZQsziU1egsXbnjXG+l
fsJmfv16k0C57EyeQLA66S7WFmjJ8dBmCx2J2WWW7etTbyU356AvZeLAiwMoGY4z
ZREemM6s2hdI6eKbartF3u+aQN8k72X8hfgAM3dl0nvfhx22CaqsR0rDk3A0tYS2
QOLnkzXpulEhidStLVLkRJw59eK4vu2CYZ37923vCvTlBctYHiRudTXQUaRQYiA+
jLdWiGiYWm6wN9TybY9GO7RY06Su1aQ2BMN8w3Why3rsRJK1ABEBAAHCwXwEGAEK
ACYWIQRmPl6KvV7s61wsJdiGpzzPhU7LmgUCYzRcLAIbDAUJAeEzgAAKCRCGpzzP
hU7Lmq0WD/46MGGZbPLp7XFh+rlotr1GBLZ0jwudoT8kkKHRpoMKRt4OZuOBjio7
3bXh74bscu1vmS1b35QvfIfiVrNOmQ8g9794598gpS7izrC/eJfenei93dqnwAMU
hEB16dEIbIevZUT3uYHNd6LgCVLdGLeauhAUZrfZ/NLvChw8+8I1Hn3Fhe5ablV7
ZfiOY/h/fC5MChBGH1izOFBkLEEeeAuaOTJKn4EYZFMitD69YGM621vCtC4jkI2g
bar8O0U9t3gyAS0WbtDz4UoMhdXOY4LIUH5KvvUby1lJq+LdS39HGvgtI+Exme0P
XajNpZBA/axARaUGyulxoz5+Y9InR0b4cIIMXWONVQ1pRglFEw6JrBvLcwS3SCfq
LW/p1ADFcLMcYMFQmJh7IYCD14gPreDELq+gmo57qDmHzaCQbh0XZB84qhIfS/cb
BFqT+0ccCLiTzAbyJeFAEu10KzLVBdUy/dysfHFevTrurObyK99MD1+6RIvNShds
gEMF3sanW3yugha6XoSd855nwiJBOJD8zff201m0IH/Dxzu/EC7zfG/SqoywZnGR
+N4bNLderqMXCgcyTcaLopQgExFMQoUmlRSHUGgPx5uXRkoTqY1V24c33lHp6G9G
GVCAGQawnWBNaJmlqoUcbIueao+hlICYiwhG/ZIP9jUceNt1LyJi9A=3D=3D
=3DRGXl
-----END PGP PUBLIC KEY BLOCK-----

--------------stx90b0AkEiL0PVX74Tu4ash--

--------------YniB4KCgR1gLpfKE9IhXHP48--

--------------hhfiFJ509NhWk10fJ1q8vqU6
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEZj5eir1e7OtcLCXYhqc8z4VOy5oFAmN+O98FAwAAAAAACgkQhqc8z4VOy5rR
qhAAtgtd3oPf6kD+C1psGbYdpRsFLRvLiTenBPdBBpzAIs8w0uDfj89/Id76ycXZeECQZSeAZp3y
Xrna+o/RPnLPawOkTxGd3A+0rATt8Z5x5XGyAC96fdplvEKY9uZM9qDRJX1Q6mBf1hlPlO4kDh5A
URyniO0DkKzY1P5nmmonFaXdQLtpBWDcILCUGFcuqTMhdruitJsEgTsz3qcWV/30i/49ESjQX84N
OjHfHMHf/xrbdYZwfcXlY33ux6oRvyirvlWy8AdkxIqU357LWlgLzqD+LVt99GEGNKRqzUFUqsBB
zNRjAPuNR0iksCd4uyXJmqwgPa/1MRs4QuGK27INYieypp7yxEudieWlTT8cRvS7TKsbDxOt7n8e
E15g/aTgn/kFTgNI/vlBSsN95E7yeEe5w8xkKKn4Gp4hYkbtIDUEMMh3RbRlka3EhCyU6PNRLmx1
+OEBszXnpxfWbLZR3pIsU+3zMXsPLMU+/FQyeTqMdDrN8sQwOAD1W5v6lHgc1WMw0yLBM+AvGaK2
BQgEjTPwvJkMrdEXdIIB35LAtsUMxK7hLas4NREawA4kdRy8wqC3BzIu+QZmIkdmtruJdEto7hgY
kT9gHKGeETxfSDmebbXL/iJCdmrwpB4bm5nF5xmOyAlMOs+6ZfOxLaL0nhb5QC2UuwbT/B83Y6PM
wjc=
=WdUf
-----END PGP SIGNATURE-----

--------------hhfiFJ509NhWk10fJ1q8vqU6--


--===============7535388174410051205==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============7535388174410051205==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung