MGASA-2017-0214
Dashboard / Vulnerabilities / MGASA-2017-0214
Summary: Updated expat packages fix security vulnerabilities
Details: Gustavo Grieco discovered an integer overflow flaw during parsing of XML. An attacker can take advantage of this flaw to cause a denial of service against an application using the Expat library (CVE-2016-9063). Rhodri James discovered an infinite loop vulnerability within the entityValueInitProcessor() function while parsing malformed XML in an external entity. An attacker can take advantage of this flaw to cause a denial of service against an application using the Expat library (CVE-2017-9233).
References: https://advisories.mageia.org/MGASA-2017-0214.html, https://bugs.mageia.org/show_bug.cgi?id=21108, https://www.debian.org/security/2017/dsa-3898
Affected packages
Package
Name: expat
Purl: pkg:rpm/mageia/expat?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
