[FEDORA-2019-613edfe68b] Fedora 31: expat

Severity High
Affected Packages 1
CVEs 1

This update of expat fixes the following security issue: * CVE-2019-15903
-- Fix heap overflow triggered by XML_GetCurrentLineNumber (or
XML_GetCurrentColumnNumber), and deny internal entities closing the doctype
The following bug fixes are also included: * Fix cases where XML_StopParser
did not have any effect when called from inside of an end element handler *
xmlwf: Fix exit code for operation without "-d DIRECTORY" previously, only
"-d DIRECTORY" would give you a proper exit code

Package Affected Version
pkg:rpm/fedora/expat?distro=fedora-31 < 2.2.8.1.fc31
Source # ID Name URL
Bugzilla 1752592 Bug #1752592 - CVE-2019-15903 expat: heap-based buffer over-read via crafted XML input https://bugzilla.redhat.com/show_bug.cgi?id=1752592
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/expat?distro=fedora-31 fedora expat < 2.2.8.1.fc31 fedora-31
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...