First published: Mon Feb 21 2022(Updated: )
It was discovered that Expat incorrectly handled certain files. An attacker could possibly use this issue to cause a crash or execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libexpat1 | <2.4.1-2ubuntu0.1 | 2.4.1-2ubuntu0.1 |
=21.10 | ||
All of | ||
ubuntu/libexpat1 | <2.2.9-1ubuntu0.2 | 2.2.9-1ubuntu0.2 |
=20.04 | ||
All of | ||
ubuntu/libexpat1 | <2.2.5-3ubuntu0.4 | 2.2.5-3ubuntu0.4 |
=18.04 | ||
All of | ||
ubuntu/libexpat1 | <2.1.0-7ubuntu0.16.04.5+esm2 | 2.1.0-7ubuntu0.16.04.5+esm2 |
=16.04 | ||
All of | ||
ubuntu/lib64expat1 | <2.1.0-7ubuntu0.16.04.5+esm2 | 2.1.0-7ubuntu0.16.04.5+esm2 |
=16.04 | ||
All of | ||
ubuntu/libexpat1 | <2.1.0-4ubuntu1.4+esm4 | 2.1.0-4ubuntu1.4+esm4 |
=14.04 | ||
All of | ||
ubuntu/lib64expat1 | <2.1.0-4ubuntu1.4+esm4 | 2.1.0-4ubuntu1.4+esm4 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-5288-1
Expat vulnerabilities
The Expat library incorrectly handles certain files, which could allow an attacker to cause a crash or execute arbitrary code.
The vulnerabilities affect Ubuntu 21.10, 20.04, 18.04, 16.04, and 14.04 versions of the libexpat1 and lib64expat1 packages.
You can find more information about the vulnerabilities in the Ubuntu security advisories: [CVE-2022-22823](https://ubuntu.com/security/CVE-2022-22823), [CVE-2021-45960](https://ubuntu.com/security/CVE-2021-45960), [CVE-2022-25235](https://ubuntu.com/security/CVE-2022-25235).