Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:14903-1

Опубликовано: 04 мар. 2022
Источник: suse-cvrf

Описание

Security update for expat

This update for expat fixes the following issues:

  • CVE-2022-25236: Fixed possible namespace-separator characters insertion into namespace URIs (bsc#1196025).
  • CVE-2022-25235: Fixed UTF-8 character validation in a certain context (bsc#1196026).
  • CVE-2022-25313: Fixed stack exhaustion in build_model() via uncontrolled recursion (bsc#1196168).
  • CVE-2022-25314: Fixed integer overflow in copyString (bsc#1196169).
  • CVE-2022-25315: Fixed integer overflow in storeRawNames (bsc#1196171).

Список пакетов

SUSE Linux Enterprise Point of Sale 11 SP3
expat-2.0.1-88.42.18.1
libexpat1-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS
expat-2.0.1-88.42.18.1
libexpat1-2.0.1-88.42.18.1
libexpat1-32bit-2.0.1-88.42.18.1

Описание

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Point of Sale 11 SP3:libexpat1-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:libexpat1-2.0.1-88.42.18.1

Ссылки

Описание

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Point of Sale 11 SP3:libexpat1-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:libexpat1-2.0.1-88.42.18.1

Ссылки

Описание

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Point of Sale 11 SP3:libexpat1-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:libexpat1-2.0.1-88.42.18.1

Ссылки

Описание

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Point of Sale 11 SP3:libexpat1-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:libexpat1-2.0.1-88.42.18.1

Ссылки

Описание

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Point of Sale 11 SP3:libexpat1-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:expat-2.0.1-88.42.18.1
SUSE Linux Enterprise Server 11 SP4-LTSS:libexpat1-2.0.1-88.42.18.1

Ссылки
Уязвимость SUSE-SU-2022:14903-1