expat-2.1.0-15.0.1.el7.AXS7

エラータID: AXSA:2024-8927:07

Release date: 
Tuesday, October 22, 2024 - 09:27
Subject: 
expat-2.1.0-15.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

This is expat, the C library for parsing XML, written by James Clark. Expat is a
stream oriented XML parser. This means that you register handlers with the
parser prior to starting the parse. These handlers are called when the parser
discovers the associated structures in the document being parsed. A start tag is
an example of the kind of structures for which you may register handlers.

Security Fix(es):

* CVE-2024-45490: Reject negative length for XML_ParseBuffer in xmlparse.c
* CVE-2024-45491: Detect integer overflow in dtdCopy on 32-bit platforms
* CVE-2024-45492: Detect integer overflow in nextScaffoldPart on 32-bit
platforms

CVE(s):
CVE-2024-45490
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
CVE-2024-45491
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
CVE-2024-45492
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

Asianux Server 7 for x86_64
  1. expat-2.1.0-15.0.1.el7.AXS7.i686.rpm
    MD5: 6ba589f21e691d01bac384026a2ef609
    SHA-256: b20c81dfafe070ca0f7cab80db39db41daace667cb1261290321eafd41f116fe
    Size: 82.36 kB
  2. expat-2.1.0-15.0.1.el7.AXS7.x86_64.rpm
    MD5: 59eace01fb5edd289b9878ec309851aa
    SHA-256: 70f18c2ab7ed807598e13f64bdb948c8fbe9950e1de50286a08a5f16783b3bef
    Size: 82.60 kB
  3. expat-devel-2.1.0-15.0.1.el7.AXS7.i686.rpm
    MD5: 5aace76b329624b99951e351cb56a13f
    SHA-256: 81918db7e017eb956a9c47b4e7b8f537ec0a6b8854c450b866d246fd543a0aef
    Size: 58.41 kB
  4. expat-devel-2.1.0-15.0.1.el7.AXS7.x86_64.rpm
    MD5: 2a47e6a75a14132fe7035b3d3c33e121
    SHA-256: f197486b9f8caf050fb5c3a0df6439f68d655ecdf1b5716ff5e352e6d52777d1
    Size: 58.38 kB