USN-7000-2: Expat vulnerabilities
USN-7000-1 fixed vulnerabilities in Expat. This update provides the corresponding updates for Ubuntu 22.04 LTS. Original advisory details: Shang-Hung Wan discovered that Expat did not properly handle certain function calls when a negative input length was provided. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45490) Shang-Hung Wan discovered that Expat did not properly handle the potential for an integer overflow on 32-bit platforms. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45491, CVE-2024-45492)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7000-2?
The severity of USN-7000-2 is rated as important due to vulnerabilities that could allow denial of service.
How do I fix USN-7000-2?
To fix USN-7000-2, update the exap and libexpat1 packages to version 2.4.7-1ubuntu0.4.
What vulnerabilities are addressed in USN-7000-2?
USN-7000-2 addresses multiple vulnerabilities related to improper input handling in Expat.
Which Ubuntu version is affected by USN-7000-2?
USN-7000-2 affects Ubuntu 22.04 LTS.
Who discovered the vulnerabilities fixed in USN-7000-2?
The vulnerabilities fixed in USN-7000-2 were discovered by Shang-Hung Wan.