Oval Definition:oval:org.mitre.oval:def:13420
Revision Date:2014-06-23Version:20
Title:DSA-1953-2 expat -- denial of service
Description:The expat updates released in DSA-1953-1 caused a regression: In some cases, expat would abort with the message "error in processing external entity reference". For the old stable distribution, this problem has been fixed in version 1.95.8-3.4+etch3. For the stable distribution, this problem has been fixed in version 2.0.1-4+lenny3. For the testing distribution and the unstable distribution , this problem will be fixed soon. We recommend that you upgrade your expat packages. For reference, the original advisory text is provided below. Jan Lieskovsky discovered an error in expat, an XML parsing C library, when parsing certain UTF-8 sequences, which can be exploited to crash an application using the library.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-3560
DSA-1953-2
Platform(s):Debian GNU/Linux 4.0
Debian GNU/Linux 5.0
Product(s):expat
Definition Synopsis
  • Release section
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture depended section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • AND Packages section
  • lib64expat1-dev DPKG is earlier than 2.0.1-4+lenny3
  • OR libexpat1 DPKG is earlier than 2.0.1-4+lenny3
  • OR libexpat1-dev DPKG is earlier than 2.0.1-4+lenny3
  • OR xpat DPKG is earlier than 2.0.1-4+lenny3
  • OR lib64expat1 DPKG is earlier than 2.0.1-4+lenny3
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is hppa
  • OR Installed architecture is armel
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is mipsel
  • OR Installed architecture is arm
  • AND Packages section
  • xpat DPKG is earlier than 2.0.1-4+lenny3
  • OR libexpat1-dev DPKG is earlier than 2.0.1-4+lenny3
  • OR libexpat1 DPKG is earlier than 2.0.1-4+lenny3
  • OR Release section
  • Debian GNU/Linux 4.0 is installed.
  • AND Packages section
  • xpat DPKG is earlier than 1.95.8-3.4+etch3
  • OR libexpat1-dev DPKG is earlier than 1.95.8-3.4+etch3
  • OR libexpat1 DPKG is earlier than 1.95.8-3.4+etch3
  • BACK