GLSA Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Sep 24, 2012 12:26 pm Post subject: [ GLSA 201209-06 ] Expat: Multiple vulnerabilities |
|
|
Gentoo Linux Security Advisory
Title: Expat: Multiple vulnerabilities (GLSA 201209-06)
Severity: normal
Exploitable: remote
Date: September 24, 2012
Bug(s): #280615, #303727, #407519
ID: 201209-06
Synopsis
Multiple vulnerabilities have been found in Expat, possibly
resulting in Denial of Service.
Background
Expat is a set of XML parsing libraries.
Affected Packages
Package: dev-libs/expat
Vulnerable: < 2.1.0_beta3
Unaffected: >= 2.1.0_beta3
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Expat. Please review
the CVE identifiers referenced below for details.
Impact
A remote attacker could entice a user to open a specially crafted XML
file in an application linked against Expat, possibly resulting in a
Denial of Service condition.
Workaround
There is no known workaround at this time.
Resolution
All Expat users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/expat-2.1.0_beta3"
| Packages which depend on this library may need to be recompiled. Tools
such as revdep-rebuild may assist in identifying some of these packages.
References
CVE-2009-3560
CVE-2009-3720
CVE-2012-0876
CVE-2012-1147
CVE-2012-1148
Last edited by GLSA on Sun Aug 17, 2014 4:31 am; edited 4 times in total |
|