You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa Expat

Sigurnosni nedostatak programskog paketa Expat

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4132-1
September 12, 2019

expat vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.04
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

Expat could be made to expose sensitive information if it received a
specially crafted XML file.

Software Description:
– expat: XML parsing C library

Details:

It was discovered that Expat incorrectly handled certain XML files.
An attacker could possibly use this issue to expose sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
libexpat1 2.2.6-1ubuntu0.19.5

Ubuntu 18.04 LTS:
libexpat1 2.2.5-3ubuntu0.2

Ubuntu 16.04 LTS:
lib64expat1 2.1.0-7ubuntu0.16.04.5
libexpat1 2.1.0-7ubuntu0.16.04.5

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4132-1
CVE-2019-15903

Package Information:
https://launchpad.net/ubuntu/+source/expat/2.2.6-1ubuntu0.19.5
https://launchpad.net/ubuntu/+source/expat/2.2.5-3ubuntu0.2
https://launchpad.net/ubuntu/+source/expat/2.1.0-7ubuntu0.16.04.5
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBAgAGBQJdep7tAAoJEEW851uECx9pGkkP/3g1Q5DmkGHUC9QNMEeyBaPO
pawz/D1r/7silxUutGbqhP1+E9Y7pz48xFdcy3bzB59Cy3TYdblhvs5CC0/3U0aO
kEHA6FbhMnj4gsg5RCGdvTg3Hrjd2EqdhduDKBy7OfQTlN0uhEVRqLkAQzvzI3TM
70ZMNj5+ZrxscJLAz6gjvRS4QS30msV+KVUxURIVUylQzVM94USJlDWTgYjPmP9q
oUPVWlzIB5kKB49HelFS2E0z0A5qdSnNAkI2VwLhB1ZWlZM6qqCsMls98xFDWoYI
xszXxu4JlvpZ0Fb3/pElhae0EC6O/59A4cjo5sP0Ms6yiuwcxbtQxSEzr6WExb0n
R/GvJbQ9fQkdfarimSIT9Je8WtGjgRvptEPSh0C8uxIxyQO6eXb4c1ls7r6/S42T
ckJ34iM0BqLLXMVKXZ6ou+GFsgHfZhEl/8RbMMvK41XLJTurUZT8R7/+PD2K9Aui
c5iMCLExk+LmYTzmMGasq/w5T6sanaVKmTyKlFWgU5qG+l4PuiuXQ7o2taExCWJj
edpeVCRyj+t2WDh49S7vSRFbbNp5HKA9eYwwecxjUQUR4Qlf5OgZaeL75f0QGqQh
QxHIK/5RkTpy0XERDYCRsJlKf36TmqprL8N2mjoPR0FwZsDX8GNqcbE8HavoN3Jj
ga8bZeqj4Y+tv0GMaD+Z
=Poov
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4132-2
September 12, 2019

expat vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 ESM
– Ubuntu 12.04 ESM

Summary:

Expat could be made to expose sensitive information if it received
a specially crafted XML file.

Software Description:
– expat: XML parsing C library

Details:

USN-4132-1 fixed a vulnerability in Expat. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.

Original advisory details:

It was discovered that Expat incorrectly handled certain XML files.
An attacker could possibly use this issue to expose sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
lib64expat1 2.1.0-4ubuntu1.4+esm2
libexpat1 2.1.0-4ubuntu1.4+esm2

Ubuntu 12.04 ESM:
lib64expat1 2.0.1-7.2ubuntu1.7
libexpat1 2.0.1-7.2ubuntu1.7

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4132-2
https://usn.ubuntu.com/4132-1
CVE-2019-15903
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBAgAGBQJdeqPxAAoJEEW851uECx9psB8P+gMgdnw4ObOyo3hFNFf0Cbnq
JXjMVsiEcXrRPw3/I6TOMa1P5bjZByRfgTpNz32UgKyZiPy8fBbg+zDAlAvyltFe
5Q2eyBgzq446z6Bg2zDVCphzgsdZ9I1UPTUjYwthbhygg4Ci/PpbuBuD5CNBPzwO
a8cyY0bBbQ2K8epKiBB6scxKzhnqALbeQ5ha1FI1RVNyDJn+ygPGgRlULW0kkRq1
d8w+5uscN6YMqG5jUu75lwW2Ch8TjBtdvyUorGJz7DV5fL3IM97y9IB30LfSujCk
7FvIG+N4WRgvKK2UhVnNBQ9af/wgg4TEthZ49tFvjpfdpQqtrptqGtBlbdpa7YDx
5ztV9IiX3M/h7P7VmLytwb19rS3l7Fo6JlpYYl1x5qkgSUof5a9wHcE0nwyseXdV
HFEp39dhONsqz/nC4jSFuxwqQfm1S/UigFjbc9yR7YT9o3f8eUyuyMpI8ymVaB57
XsXS1zEIdBZhOazQAz52RfjTSblwpQWFAgyBan4HHBzsUdN9VJDSTv9rDr3QyPSS
qPDkr+oZgYSMQRAnfhh2RHrW5A/emX+ExeswFYPubWg+ckYezO8TXzjOihH1ubLa
Cm396yLGadF9q4OdWR+LOhvx8FKJcZrsomW4OR/qQG1Xp7u4NaZwvc78aHW79eJa
n6oXQrGrUj/cgnFygUSU
=oI5V
—–END PGP SIGNATURE—–

AutorJosip Papratovic
Cert idNCERT-REF-2019-09-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa OpenShift Enterprise

Otkriveni su sigurnosni nedostaci u programskom paketu OpenShift Enterprise za operacijski sustav RHEL. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS...

Close