Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2020:4484

Опубликовано: 03 нояб. 2020
Источник: rocky
Оценка: Moderate

Описание

Moderate: expat security update

Expat is a C library for parsing XML documents.

Security Fix(es):

  • expat: large number of colons in input makes parser consume high amount of resources, leading to DoS (CVE-2018-20843)

  • expat: heap-based buffer over-read via crafted XML input (CVE-2019-15903)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.3 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
expati6864.el8expat-2.2.5-4.el8.i686.rpm
expati6864.el8expat-2.2.5-4.el8.i686.rpm
expatx86_644.el8expat-2.2.5-4.el8.x86_64.rpm
expatx86_644.el8expat-2.2.5-4.el8.x86_64.rpm
expat-develi6864.el8expat-devel-2.2.5-4.el8.i686.rpm
expat-develi6864.el8expat-devel-2.2.5-4.el8.i686.rpm
expat-develx86_644.el8expat-devel-2.2.5-4.el8.x86_64.rpm
expat-develx86_644.el8expat-devel-2.2.5-4.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
около 5 лет назад

ELSA-2020-4484: expat security update (MODERATE)

oracle-oval
около 5 лет назад

ELSA-2020-3952: expat security update (MODERATE)

CVSS3: 7.5
ubuntu
больше 6 лет назад

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).

CVSS3: 7.5
redhat
больше 6 лет назад

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).

CVSS3: 7.5
nvd
больше 6 лет назад

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).