RHSA-2016:2824: Moderate: expat security update
Expat is a C library for parsing XML documents.Security Fix(es): An out-of-bounds read flaw was found in the way Expat processed certain input. A remote attacker could send specially crafted XML that, when parsed by an application using the Expat library, would cause that application to crash or, possibly, execute arbitrary code with the permission of the user running the application. (CVE-2016-0718) Red Hat would like to thank Gustavo Grieco for reporting this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:2824?
The severity of RHSA-2016:2824 is classified as moderate.
How do I fix RHSA-2016:2824?
To fix RHSA-2016:2824, update the Expat package to version 2.1.0-10.el7_3 or higher.
What systems are affected by RHSA-2016:2824?
RHSA-2016:2824 affects multiple versions of the Expat library including those on Red Hat Enterprise Linux 6 and 7.
What type of vulnerability is addressed in RHSA-2016:2824?
RHSA-2016:2824 addresses an out-of-bounds read vulnerability in the Expat XML parsing library.
Is RHSA-2016:2824 applicable to Expat-devel and Expat-static packages?
Yes, RHSA-2016:2824 applies to both Expat-devel and Expat-static packages in the specified versions.