Vulnerability Database
Blog
FAQ
Docs
ALSA-2024:1530
See a problem?
Please try reporting it
to the source
first.
Source
https://errata.almalinux.org/9/ALSA-2024-1530.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2024:1530.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2024:1530
Related
CVE-2023-52425
CVE-2024-28757
Published
2024-03-26T00:00:00Z
Modified
2024-04-02T08:32:06Z
Summary
Moderate: expat security update
Details
Expat is a C library for parsing XML documents.
Security Fix(es):
expat: parsing large tokens can trigger a denial of service (CVE-2023-52425)
expat: XML Entity Expansion (CVE-2024-28757)
References
https://access.redhat.com/errata/RHSA-2024:1530
https://access.redhat.com/security/cve/CVE-2023-52425
https://access.redhat.com/security/cve/CVE-2024-28757
https://bugzilla.redhat.com/2262877
https://bugzilla.redhat.com/2268766
https://errata.almalinux.org/9/ALSA-2024-1530.html
Affected packages
AlmaLinux:9
/
expat
Package
Name
expat
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.5.0-1.el9_3.1
AlmaLinux:9
/
expat-devel
Package
Name
expat-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.5.0-1.el9_3.1
ALSA-2024:1530 - OSV