New Debian expat 2.5.0-1+deb12u2 fixes: This update addresses the following issues: 2.5.0-1+deb12u2 (Sat, 05 Apr 2025 07:36:55 +0200) [ Tomas Korbar <tkorbar@redhat.com> ] * Backport security fix for CVE-2023-52425: denial of service with really big tokens. * Backport security fix for CVE-2024-50602: crash within the XML_ResumeParser() function because XML_StopParser can stop/suspend an unstarted parser. * Backport security fix for CVE-2024-8176: long linear chains of entities crash with stack overflow. [ Laszlo Boszormenyi (GCS) ] * Update libexpat1 symbols.
--- mirror/ftp/pool/main/e/expat/expat_2.5.0-1+deb12u1.dsc +++ apt/ucs_5.2-0-errata5.2-3/source/expat_2.5.0-1+deb12u2.dsc @@ -1,3 +1,17 @@ +2.5.0-1+deb12u2 [Sat, 05 Apr 2025 07:36:55 +0200] Laszlo Boszormenyi (GCS) <gcs@debian.org>: + + [ Tomas Korbar <tkorbar@redhat.com> ] + * Backport security fix for CVE-2023-52425: denial of service with really + big tokens. + * Backport security fix for CVE-2024-50602: crash within the + XML_ResumeParser() function because XML_StopParser can stop/suspend an + unstarted parser. + * Backport security fix for CVE-2024-8176: long linear chains of entities + crash with stack overflow. + + [ Laszlo Boszormenyi (GCS) ] + * Update libexpat1 symbols. + 2.5.0-1+deb12u1 [Sun, 08 Sep 2024 08:44:19 +0200] Laszlo Boszormenyi (GCS) <gcs@debian.org>: * Backport security fix for CVE-2024-45490: reject negative len for <http://piuparts.knut.univention.de/5.2-3/#9206997145296600061>
OK: YAML OK: Tests OK: piuparts
<https://errata.software-univention.de/#/?erratum=5.2x190>