Debian alert DLA-3783-1 (expat)
| From: | Tobias Frost <tobi@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 3783-1] expat security update | |
| Date: | Tue, 09 Apr 2024 06:41:36 +0200 | |
| Message-ID: | <ZhTHAKjoijTwibiw@isildor2.loewenhoehle.ip> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-3783-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Tobias Frost April 07, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : expat Version : 2.2.6-2+deb10u7 CVE ID : CVE-2023-52425 Debian Bug : 1063238 Expat, an XML parsing C library has been found to have an vulnerability that allows an attacker to perform a denial of service (resource consumption, when many full reparsings are required in the case of a large tokens. When parsing a really big token that requires multiple buffer fills to complete, expat has to re-parse the token from start multiple times, which takes time. These patches introduce a heuristic that, when having failed on the same token multiple times, defers further parsing until there's significantly more data available. The patch also introduces an optiional API, XML_SetReparseDeferralEnabled(), to disable the new heuristic. For Debian 10 buster, this problem has been fixed in version 2.2.6-2+deb10u7. We recommend that you upgrade your expat packages. For the detailed security status of expat please refer to its security tracker page at: https://security-tracker.debian.org/tracker/expat Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEE/d0M/zhkJ3YwohhskWT6HRe9XTYFAmYUxv0ACgkQkWT6HRe9 XTZJ9BAApYPi2xKWBS6RkCfv5LiEt2xk2k4bdrDZwdnhbYRDBqbMaaqH2R1vc7hH GIj6ahbaG/fOO46Qr1k8Yn1SSKsfxrBeiz6gkY10Bq/z29v5uLzp6Ew0cDB49Wxe 3Tm2Vy8HIjMim3dque8qce8qGfiY3iygL12o67weM8nn62a7lu6RIlmIwGqKxplD 5O2j6Bx9B1Z5JrgYJnr5ZcEYRf/Naumyz2uScvtdzjexw+0SfoeVPDykfAdIFNTc FgHUV3ZZTEnNWBcMVKKgeOD/HmNJswmQimFyBMDXKe1O1JuulVkww427nYCS9guP iSCIbhDSfPbrjzHU1lwut8kWydHNcp/86DtCjcs9hWgAQ+byeLCLBGKsG0QfYQY8 +4pUHllxuAzfNgZ5wLqV51U0/qWoJpg7+rt8D/zSYtNPXq9x/w6lEtHVdLF0glfm OgLAuPi/Yh2eFt3dZUkz7WqOKc5l4xK5F5Br+4HCdj63lFfumyUn+AlQV+SjV4tV 6ce/eDJHw1WZJu/XJsBHZOkgi1s/2xvUEjcJQ4KGjKvzwMGq/+pTYaUHxzrYqhBi jcuMHA1ILXKAogyZ0xhYt0HmALo7NdL+brAkoTEWcIlKniu0BrwgOWqZ2gJwVgLe hGTk8Usglo90e6X4owKGTN9ioRTbg+rf8v8FqWzUGgL5VNMoC18= =wR3u -----END PGP SIGNATURE-----
