Univention Bugzilla – Full Text Bug Listing |
Summary: | expat: Mehrere Sicherheitslücken (4.1) | ||
---|---|---|---|
Product: | UCS | Reporter: | Arvid Requate <requate> |
Component: | Security updates | Assignee: | Arvid Requate <requate> |
Status: | CLOSED FIXED | QA Contact: | Philipp Hahn <hahn> |
Severity: | normal | ||
Priority: | P4 | Flags: | requate:
Patch_Available+
|
Version: | UCS 4.1 | ||
Target Milestone: | UCS 4.1-4-errata | ||
Hardware: | Other | ||
OS: | Linux | ||
What kind of report is it?: | Security Issue | What type of bug is this?: | --- |
Who will be affected by this bug?: | --- | How will those affected feel about the bug?: | --- |
User Pain: | Enterprise Customer affected?: | ||
School Customer affected?: | ISV affected?: | ||
Waiting Support: | Flags outvoted (downgraded) after PO Review: | ||
Ticket number: | Bug group (optional): | Security | |
Max CVSS v3 score: | |||
Bug Depends on: | |||
Bug Blocks: | 42570 |
Description
Arvid Requate
2015-09-28 18:16:01 CEST
Upstream Debian package version 2.1.0-1+deb7u3 fixes this additional issue: * Out-of-bounds heap read on crafted input causing crash or code execution (CVE-2016-0718) Two additional issues have been fixed in the Jessie package version: * unanticipated internal calls to srand (CVE-2012-6702) * use of too little entropy (CVE-2016-5300) Fixed in 2.1.0-1+deb7u4 Advisory: expat.yaml OK: errata-announce -V --only expat.yaml OK: expat.yaml OK: aptitude install '?source-package(expat)~i' OK: aptitude install '?source-package(expat)' OK: zless /usr/share/doc/expat/changelog.Debian.gz # 2.1.0-1+deb7u4 FYI: Also fixes CVE-2016-0719, which is =0718 OK: /usr/bin/xmlwf /var/lib/gconf/defaults/%gconf-tree.xml |