gpp_maybe
Security update for expat
SUSE-SLE-SAP-12-SP4-2022-179
This update for expat fixes the following issues: - CVE-2021-45960: Fixed left shift in the storeAtts function in xmlparse.c that can lead to realloc misbehavior (bsc#1194251). - CVE-2021-46143: Fixed integer overflow in m_groupSize in doProlog (bsc#1194362). - CVE-2022-22822: Fixed integer overflow in addBinding in xmlparse.c (bsc#1194474). - CVE-2022-22823: Fixed integer overflow in build_model in xmlparse.c (bsc#1194476). - CVE-2022-22824: Fixed integer overflow in defineAttribute in xmlparse.c (bsc#1194477). - CVE-2022-22825: Fixed integer overflow in lookup in xmlparse.c (bsc#1194478). - CVE-2022-22826: Fixed integer overflow in nextScaffoldPart in xmlparse.c (bsc#1194479). - CVE-2022-22827: Fixed integer overflow in storeAtts in xmlparse.c (bsc#1194480).
-
Release DateJan 25 2022
-
ReferencesBugzilla: 1194251, 1194362, 1194474, 1194476, 1194477, 1194478, 1194479, 1194480
CVEs: CVE-2021-45960, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.4 ppc64le
-
Packages
SUSE Linux Enterprise Server for SAP Applications 12.4 x86_64
-
Packagesexpat
XML Parser Toolkitlibexpat12.1.0-21.12.1 lock rpm lock src
XML Parser Toolkitlibexpat1-32bit2.1.0-21.12.1 lock rpm
XML Parser Toolkit2.1.0-21.12.1 lock rpm