drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Denial of Service in Expat
| Name: |
Denial of Service in Expat |
|
| ID: |
USN-7424-1 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 24.10 |
|
| Datum: |
Di, 8. April 2025, 14:44 |
|
| Referenzen: |
https://www.cve.org/CVERecord?id=CVE-2024-8176 |
|
| Applikationen: |
expat |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============2691155427137952230== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------FPe0Odp90XC4ILWCOYFVQVt8"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------FPe0Odp90XC4ILWCOYFVQVt8 Content-Type: multipart/mixed; boundary="------------Mb01UIBHQW91x0bUULP060Cx"; protected-headers="v1" From: Vyom Yadav <vyom.yadav@canonical.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <3eb840e1-b1bc-4cf7-bfb6-7fd4639d1194@canonical.com> Subject: [USN-7424-1] Expat vulnerability
--------------Mb01UIBHQW91x0bUULP060Cx Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-7424-1 April 08, 2025
expat vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS
Summary:
Expat could be made to crash if it received specially crafted input.
Software Description: - expat: XML parsing C library
Details:
It was discovered that Expat could crash due to stack overflow when processing XML documents with deeply nested entity references. If a user or automated system were tricked into processing specially crafted XML input, an attacker could use this issue to cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10 expat 2.6.2-2ubuntu0.2 libexpat1 2.6.2-2ubuntu0.2
Ubuntu 24.04 LTS expat 2.6.1-2ubuntu0.3 libexpat1 2.6.1-2ubuntu0.3
Ubuntu 22.04 LTS expat 2.4.7-1ubuntu0.6 libexpat1 2.4.7-1ubuntu0.6
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-7424-1 CVE-2024-8176
Package Information: https://launchpad.net/ubuntu/+source/expat/2.6.2-2ubuntu0.2 https://launchpad.net/ubuntu/+source/expat/2.6.1-2ubuntu0.3 https://launchpad.net/ubuntu/+source/expat/2.4.7-1ubuntu0.6
--------------Mb01UIBHQW91x0bUULP060Cx--
--------------FPe0Odp90XC4ILWCOYFVQVt8 Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc"
-----BEGIN PGP SIGNATURE-----
wnsEABYIACMWIQSV2d7RU755utSnx3O7Ba3EKYsoKQUCZ/UP0QUDAAAAAAAKCRC7Ba3EKYsoKd6u AP4t8fcua6mmwlCcs/EQlQe66PnaoCNuXaTFVaSboulXPwEAzx2vvAv6Xz1stucqebXOuYA+2G/s nX03RILfLGHFrgA= =oTLi -----END PGP SIGNATURE-----
--------------FPe0Odp90XC4ILWCOYFVQVt8--
--===============2691155427137952230== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============2691155427137952230==--
|
|
|
|