First published: Mon Nov 28 2016(Updated: )
Expat is a C library for parsing XML documents.<br>Security Fix(es):<br><li> An out-of-bounds read flaw was found in the way Expat processed certain input. A remote attacker could send specially crafted XML that, when parsed by an application using the Expat library, would cause that application to crash or, possibly, execute arbitrary code with the permission of the user running the application. (CVE-2016-0718)</li> Red Hat would like to thank Gustavo Grieco for reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/expat | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-debuginfo | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-debuginfo | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-devel | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-devel | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-static | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-static | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat | <2.0.1-13.el6_8 | 2.0.1-13.el6_8 |
redhat/expat | <2.0.1-13.el6_8 | 2.0.1-13.el6_8 |
redhat/expat-debuginfo | <2.0.1-13.el6_8 | 2.0.1-13.el6_8 |
redhat/expat-debuginfo | <2.0.1-13.el6_8 | 2.0.1-13.el6_8 |
redhat/expat-devel | <2.0.1-13.el6_8 | 2.0.1-13.el6_8 |
redhat/expat-devel | <2.0.1-13.el6_8 | 2.0.1-13.el6_8 |
redhat/expat | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-debuginfo | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-devel | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
redhat/expat-static | <2.1.0-10.el7_3 | 2.1.0-10.el7_3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2016:2824 is classified as moderate.
To fix RHSA-2016:2824, update the Expat package to version 2.1.0-10.el7_3 or higher.
RHSA-2016:2824 affects multiple versions of the Expat library including those on Red Hat Enterprise Linux 6 and 7.
RHSA-2016:2824 addresses an out-of-bounds read vulnerability in the Expat XML parsing library.
Yes, RHSA-2016:2824 applies to both Expat-devel and Expat-static packages in the specified versions.