Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in Expat
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in Expat
ID: USN-4132-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 19.04
Datum: Do, 12. September 2019, 23:30
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15903
Applikationen: expat

Originalnachricht


--===============1512508435186266526==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature";
boundary="vtzGhvizbBRQ85DL"
Content-Disposition: inline


--vtzGhvizbBRQ85DL
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4132-1
September 12, 2019

expat vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Expat could be made to expose sensitive information if it received a
specially crafted XML file.

Software Description:
- expat: XML parsing C library

Details:

It was discovered that Expat incorrectly handled certain XML files.
An attacker could possibly use this issue to expose sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
libexpat1 2.2.6-1ubuntu0.19.5

Ubuntu 18.04 LTS:
libexpat1 2.2.5-3ubuntu0.2

Ubuntu 16.04 LTS:
lib64expat1 2.1.0-7ubuntu0.16.04.5
libexpat1 2.1.0-7ubuntu0.16.04.5

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4132-1
CVE-2019-15903

Package Information:
https://launchpad.net/ubuntu/+source/expat/2.2.6-1ubuntu0.19.5
https://launchpad.net/ubuntu/+source/expat/2.2.5-3ubuntu0.2
https://launchpad.net/ubuntu/+source/expat/2.1.0-7ubuntu0.16.04.5

--vtzGhvizbBRQ85DL
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJdep7tAAoJEEW851uECx9pGkkP/3g1Q5DmkGHUC9QNMEeyBaPO
pawz/D1r/7silxUutGbqhP1+E9Y7pz48xFdcy3bzB59Cy3TYdblhvs5CC0/3U0aO
kEHA6FbhMnj4gsg5RCGdvTg3Hrjd2EqdhduDKBy7OfQTlN0uhEVRqLkAQzvzI3TM
70ZMNj5+ZrxscJLAz6gjvRS4QS30msV+KVUxURIVUylQzVM94USJlDWTgYjPmP9q
oUPVWlzIB5kKB49HelFS2E0z0A5qdSnNAkI2VwLhB1ZWlZM6qqCsMls98xFDWoYI
xszXxu4JlvpZ0Fb3/pElhae0EC6O/59A4cjo5sP0Ms6yiuwcxbtQxSEzr6WExb0n
R/GvJbQ9fQkdfarimSIT9Je8WtGjgRvptEPSh0C8uxIxyQO6eXb4c1ls7r6/S42T
ckJ34iM0BqLLXMVKXZ6ou+GFsgHfZhEl/8RbMMvK41XLJTurUZT8R7/+PD2K9Aui
c5iMCLExk+LmYTzmMGasq/w5T6sanaVKmTyKlFWgU5qG+l4PuiuXQ7o2taExCWJj
edpeVCRyj+t2WDh49S7vSRFbbNp5HKA9eYwwecxjUQUR4Qlf5OgZaeL75f0QGqQh
QxHIK/5RkTpy0XERDYCRsJlKf36TmqprL8N2mjoPR0FwZsDX8GNqcbE8HavoN3Jj
ga8bZeqj4Y+tv0GMaD+Z
=Poov
-----END PGP SIGNATURE-----

--vtzGhvizbBRQ85DL--


--===============1512508435186266526==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung