it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5085-2] expat regression update
- Date: Sun, 13 Mar 2022 15:15:49 +0000
- List-archive: https://lists.debian.org/msgid-search/E1nTPwj-0004eu-Uu AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=RFb0DhrUqV9F+jSAVGES+08BvctGQulAFonyKXmiP64=; b=Sx 45H7JZAdBDB1De1hhX9eln4tG1dIkoVLim59L+9hh7p95danSkYD6XYmsQXA4Ugv1UHgMl+Z4gWAo ZKPNHL2HocOL1IcNas0c0vrB0a7lhHnLLlQoHiW7ufrh8ncZDxUvq5cSQge9qykemsgT1k102PzO+ AXCz4iZUXvXkI6ZRVfKzTBxj4LsVfOrfl9vJD49x3WllbJJmGsrBSo5tIzKf8dQ+ts5nlLPa8Bu+9 d2hLjfF2hz0SGA3T32eIv6KicpGeaXgp/KDWn6AUJtFX2wMa+aqen+l3gdaFMlP98b9GSS/8tXRIU WUxuW8g8AiCcfm+VWp7mNwHBzUsEVKqQ==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Sun, 13 Mar 2022 15:16:05 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <gnXee_0RSaK.A.w4G.1qgLiB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5085-2 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
March 13, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : expat
The update for expat released as DSA 5085-1 introduced regressions for
applications using URI characters (':' in particular) for a namespace
separator (while the HTML API docs of function XML_ParserCreateNS have
been advising against their use). Updated expat packages are now
available which relax the fix for CVE-2022-25236 with regard to RFC 3986
URI characters.
For the oldstable distribution (buster), this problem has been fixed
in version 2.2.6-2+deb10u4.
For the stable distribution (bullseye), this problem has been fixed in
version 2.2.10-2+deb11u3.
We recommend that you upgrade your expat packages.
For the detailed security status of expat please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/expat
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmIuCg1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0T4Qg/9FtaNcCnoiyq8BwF4PCakVyzNS3wtnYgzrrG7mT1K9cxBEw9soLFEvEGE
Lxig6KVBzIcFS1iXVJCXLu8yAYGuNDSXeZpitzZgwjP7eo/zYQwhVmwUsDiDCQGb
CaxFlGGPV/KnWSkKJ5M0AF+kz8fHFm6RYyN/KxahL8z6iYlQN26P7YvDAAdY5r8q
IDiQ17x69gwGb3rHByFidMXRZSYeZYdoFdz+g+gjVNExe/9cQ/c2DxoElSK2pKOL
VKG6hVZA+ieQX286VqrCbjqmzwyHO2mEv1OdVgLzPvl8bvPiQJM2pv7hlEA/WdjR
XMbqCEwrsTkcl26m5zWdCzUC0b5UEWnBz5/uLGMHemmPUFo6cccX/Ozbzxucl5JI
eqfAlTgsk/DQZY+soHCPfu0PrtnXGRMEpeaU+LFfGNHeHGKcFIWan1sQ5lBjP3Lu
Jw7ewDtkpoiV5TMeMsc3kFOVlWNbI0AMiEtzx31IjMfvgsqKiYTH3R69YEx4Fm5L
CDsTFsxrIVD7O9yyqIrqD8ZYuYRcLm9lwv8Ib0hIDZk9au8612Cr2JYJPlJqAkVi
/exZ8bj5FAZ6wB5sU+CLcDt9kLe/Nj46i0PZJIfR6uHRy6SrhLxp8hP69+LXM+oP
33wNIvyGXSlzIL/ep7HvOn03areJmh514U2eL9EHPchp2Cqi5sQ=
=kJLT
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5085-2] expat regression update, Salvatore Bonaccorso, 14.03.2022
Archiv bereitgestellt durch MHonArc 2.6.24.