USN-7001-2: xmltok library vulnerabilities
USN-7001-1 fixed vulnerabilities in xmltol library. This update provides the corresponding updates for Ubuntu 24.04 LTS. Original advisory details: Shang-Hung Wan discovered that Expat, contained within the xmltok library, did not properly handle certain function calls when a negative input length was provided. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45490) Shang-Hung Wan discovered that Expat, contained within the xmltok library, did not properly handle the potential for an integer overflow on 32-bit platforms. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45491)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7001-2?
USN-7001-2 addresses critical vulnerabilities in the xmltok library that could allow for denial of service or other exploits.
How do I fix USN-7001-2?
To fix USN-7001-2, upgrade the libxmltok1t64 package to version 1.2-4.1ubuntu2.24.0.4.1+esm1 on Ubuntu 24.04.
What vulnerabilities are addressed in USN-7001-2?
USN-7001-2 addresses vulnerabilities identified as CVE-2024-45490 and CVE-2024-45491 in the xmltok library.
Is USN-7001-2 applicable to all Ubuntu versions?
No, USN-7001-2 specifically applies to Ubuntu 24.04 LTS.
What is the source of the vulnerabilities fixed in USN-7001-2?
The vulnerabilities fixed in USN-7001-2 were discovered by Shang-Hung Wan in the Expat library used within the xmltok component.