Debian Security Advisory

DSA-3318-1 expat -- security update

Date Reported:
26 Jul 2015
Affected Packages:
expat
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 793484.
In Mitre's CVE dictionary: CVE-2015-1283.
More information:

Multiple integer overflows have been discovered in Expat, an XML parsing C library, which may result in denial of service or the execution of arbitrary code if a malformed XML file is processed.

For the oldstable distribution (wheezy), this problem has been fixed in version 2.1.0-1+deb7u2.

For the stable distribution (jessie), this problem has been fixed in version 2.1.0-6+deb8u1.

For the unstable distribution (sid), this problem has been fixed in version 2.1.0-7.

We recommend that you upgrade your expat packages.