[SUSE-SU-2022:2294-1] Security update for expat

Severity Important
Affected Packages 14
CVEs 5

Security update for expat

This update for expat fixes the following issues:

  • CVE-2022-25236: Fixed possible namespace-separator characters insertion into namespace URIs (bsc#1196025).
  • Fixed a regression caused by the patch for CVE-2022-25236 (bsc#1196784).
  • CVE-2022-25235: Fixed UTF-8 character validation in a certain context (bsc#1196026).
  • CVE-2022-25313: Fixed stack exhaustion in build_model() via uncontrolled recursion (bsc#1196168).
  • CVE-2022-25314: Fixed integer overflow in copyString (bsc#1196169).
  • CVE-2022-25315: Fixed integer overflow in storeRawNames (bsc#1196171).
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/libexpat1?arch=x86_64&distro=opensuse-leap-15.4 suse libexpat1 < 2.4.4-150400.3.6.9 opensuse-leap-15.4 x86_64
Affected pkg:rpm/suse/libexpat1?arch=s390x&distro=opensuse-leap-15.4 suse libexpat1 < 2.4.4-150400.3.6.9 opensuse-leap-15.4 s390x
Affected pkg:rpm/suse/libexpat1?arch=ppc64le&distro=opensuse-leap-15.4 suse libexpat1 < 2.4.4-150400.3.6.9 opensuse-leap-15.4 ppc64le
Affected pkg:rpm/suse/libexpat1?arch=aarch64&distro=opensuse-leap-15.4 suse libexpat1 < 2.4.4-150400.3.6.9 opensuse-leap-15.4 aarch64
Affected pkg:rpm/suse/libexpat1-32bit?arch=x86_64&distro=opensuse-leap-15.4 suse libexpat1-32bit < 2.4.4-150400.3.6.9 opensuse-leap-15.4 x86_64
Affected pkg:rpm/suse/libexpat-devel?arch=x86_64&distro=opensuse-leap-15.4 suse libexpat-devel < 2.4.4-150400.3.6.9 opensuse-leap-15.4 x86_64
Affected pkg:rpm/suse/libexpat-devel?arch=s390x&distro=opensuse-leap-15.4 suse libexpat-devel < 2.4.4-150400.3.6.9 opensuse-leap-15.4 s390x
Affected pkg:rpm/suse/libexpat-devel?arch=ppc64le&distro=opensuse-leap-15.4 suse libexpat-devel < 2.4.4-150400.3.6.9 opensuse-leap-15.4 ppc64le
Affected pkg:rpm/suse/libexpat-devel?arch=aarch64&distro=opensuse-leap-15.4 suse libexpat-devel < 2.4.4-150400.3.6.9 opensuse-leap-15.4 aarch64
Affected pkg:rpm/suse/libexpat-devel-32bit?arch=x86_64&distro=opensuse-leap-15.4 suse libexpat-devel-32bit < 2.4.4-150400.3.6.9 opensuse-leap-15.4 x86_64
Affected pkg:rpm/suse/expat?arch=x86_64&distro=opensuse-leap-15.4 suse expat < 2.4.4-150400.3.6.9 opensuse-leap-15.4 x86_64
Affected pkg:rpm/suse/expat?arch=s390x&distro=opensuse-leap-15.4 suse expat < 2.4.4-150400.3.6.9 opensuse-leap-15.4 s390x
Affected pkg:rpm/suse/expat?arch=ppc64le&distro=opensuse-leap-15.4 suse expat < 2.4.4-150400.3.6.9 opensuse-leap-15.4 ppc64le
Affected pkg:rpm/suse/expat?arch=aarch64&distro=opensuse-leap-15.4 suse expat < 2.4.4-150400.3.6.9 opensuse-leap-15.4 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...