Revision Date: | 2022-07-06 | Version: | 1 |
Title: | (Important) |
Description: |
This update for expat fixes the following issues:
- CVE-2022-25236: Fixed possible namespace-separator characters insertion into namespace URIs (bsc#1196025). - Fixed a regression caused by the patch for CVE-2022-25236 (bsc#1196784). - CVE-2022-25235: Fixed UTF-8 character validation in a certain context (bsc#1196026). - CVE-2022-25313: Fixed stack exhaustion in build_model() via uncontrolled recursion (bsc#1196168). - CVE-2022-25314: Fixed integer overflow in copyString (bsc#1196169). - CVE-2022-25315: Fixed integer overflow in storeRawNames (bsc#1196171).
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1196025 1196026 1196168 1196169 1196171 1196784 CVE-2013-1985 CVE-2022-25235 CVE-2022-25236 CVE-2022-25313 CVE-2022-25314 CVE-2022-25315
|
Platform(s): | Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure SUSE Linux Enterprise Desktop 15 SP2 SUSE Linux Enterprise High Performance Computing 15 SP2 SUSE Linux Enterprise Module for Desktop Applications 15 SP2 SUSE Linux Enterprise Server 15 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SP2 SUSE Linux Enterprise Storage 7 SUSE Manager Proxy 4.1 SUSE Manager Server 4.1
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed AND libXinerama1-32bit-1.1.3-1.22 is installed
|
Definition Synopsis |
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure is installed
AND libexpat1-2.4.4-150400.3.6.9 is installed
|