it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5236-1] expat security update
- Date: Thu, 22 Sep 2022 20:17:33 +0000
- Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/E1obSdZ-00GVEQ-2K AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=cn46rgml6pzIa5de6ce3YNK/mrCVtI2gT4I8irhxQxg=; b=Dx WYvVhdbQiGtnVDXrSnPsJ8KkWjyTafFn3GD7DdtVhp8dwvYa2Wd/QWe5+sdIe+I9kRqlbY11X3BWD 2B8I1zmPGPuH+91584oi9P054BSeSW4KeVbkn1OCHPLHX6dR0ylGgeJxQMOKd3wCU1LmslcAEI3np YlO7st1pD3lI2QO18JOgmCRaxsf89vEGP76flL/8KbXXCsOdsETf7D8WHAdRbeIqMLODxwKU7/45M S7bkuISxZBIeyeXMZIWuJJJw/2WLIYQTOiq7NugUhZtzaLpZSPaOnxEDfzcklNlOqzIf/BrUFdzDR nX8W0C8WN+V8KmfT85BRTjuEeVWqx1tg==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Thu, 22 Sep 2022 20:17:57 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <CFQm7YLaeLM.A.THH.1LMLjB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5236-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
September 22, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : expat
CVE ID : CVE-2022-40674
Debian Bug : 1019761
Rhodri James discovered a heap use-after-free vulnerability in the
doContent function in Expat, an XML parsing C library, which could
result in denial of service or potentially the execution of arbitrary
code, if a malformed XML file is processed.
For the stable distribution (bullseye), this problem has been fixed in
version 2.2.10-2+deb11u4.
We recommend that you upgrade your expat packages.
For the detailed security status of expat please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/expat
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmMswX5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0S/8Q//fGZXIhVvGp/MCAlvkFtooR1PDtteATpnqNqxC80S2CbP89Te7qMajS5d
WpfotIGIMm3HBi/gZf1Cn778TQBijdWBR5cvcf1zV6EmInpSkKUt8miGKQ91YGig
/8CnVwnzxSTSlaxaAbC6OqKW6FK9r0U2b7vlOw4z2NjhBclNMvk9tP6iWi8+iQgR
jz4mqygHdY/aoaOLKAEKXdmzV3MOwv/Kk4qeSAKU9CtPya2KUEos3qLrGVOjQXqN
/RCZzW/YYn3DhPmDGqoSMw8LIh29CML0CtV46Ojz/YI4PtryF0i0gC3cF5w2OnjA
Xr46sMqLw2XvqXtcjqfRtX1pcHtiqhGvhBYZh1CRc04YtMIXIeLtVY0vKzgZaUze
vN1tNtacuGoXaGN5I2IqSbufTvaPOGwJ/IG9mOrSXrPQ4g/meWAVIoMTqdCv6Min
VFxaNHrfmNcVWrgwA+1+RX8iciN76Q3p/evgbs0RBaXZAfrhj4jqa7nfedfr5iNx
BCjVe4y1MyfUfLx96B5OLX9eR/Zx/h6cQiqSjZfY4qxbwiDlvmUVrphg3EzaTZr4
u4VvOVw6BHpy0hWHYLHu8bfPmWarV6m5zdYnxSWgusimzZjtJXc30N0Jl0BmO07P
UaKoRg3O8Pb0Ijq+2g8q0hV4RzCxdOx7g2/p2peorDcq/KgvxvY=
=tg+s
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5236-1] expat security update, Salvatore Bonaccorso, 22.09.2022
Archiv bereitgestellt durch MHonArc 2.6.24.