From b9fc63c20df1fdeead24c989c4aca4090830f9d4 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 1 Nov 2022 03:06:32 +0000 Subject: gentoo auto-resync : 01:11:2022 - 03:06:31 --- metadata/glsa/glsa-202210-38.xml | 42 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 metadata/glsa/glsa-202210-38.xml (limited to 'metadata/glsa/glsa-202210-38.xml') diff --git a/metadata/glsa/glsa-202210-38.xml b/metadata/glsa/glsa-202210-38.xml new file mode 100644 index 000000000000..82ab94939724 --- /dev/null +++ b/metadata/glsa/glsa-202210-38.xml @@ -0,0 +1,42 @@ + + + + Expat: Denial of Service + A vulnerability has been found in Expat which could result in denial of service. + expat + 2022-10-31 + 2022-10-31 + 878271 + remote + + + 2.5.0 + 2.5.0 + + + +

Expat is a set of XML parsing libraries.

+
+ +

In certain out-of-memory situations, Expat may free memory before it should, leading to a use-after-free.

+
+ +

A use-after-free can result in denial of service.

+
+ +

There is no known workaround at this time.

+
+ +

All Expat users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/expat-2.5.0" + +
+ + CVE-2022-43680 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3