PSF-2017-11
Dashboard / Vulnerabilities / PSF-2017-11
PSF-2017-11
Summary: Expat 2.2.3
Details: Expat 2.2.2 was released with multiple security fixes: * #43: Protect against compilation without any source of high quality entropy enabled, e.g. with CMake build system * #60: Windows with _UNICODE: Unintended use of LoadLibraryW with a non-wide string resulted in failure to load advapi32.dll and degradation in quality of used entropy when compiled with _UNICODE for Windows; you can launch existing binaries with EXPAT_ENTROPY_DEBUG=1 in the environment to inspect the quality of entropy used during runtime * [MOX-006]: Fix non-NULL parser parameter validation in XML_Parse; resulted in NULL dereference, previously Expat 2.2.3 contains an additional security fix: #82: CVE-2017-11742 -- Windows: Fix DLL hijacking vulnerability using Steve Holme's LoadLibrary wrapper for/of cURL
References: https://bugs.python.org/issue30947
Affected packages
Package
Name:
Purl:
