Bug 30070 - expat new security issues CVE-2022-2523[56], CVE-2022-2531[345]
Summary: expat new security issues CVE-2022-2523[56], CVE-2022-2531[345]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-02-19 20:30 CET by Thomas Backlund
Modified: 2022-02-23 18:42 CET (History)
4 users (show)

See Also:
Source RPM: expat
CVE:
Status comment:


Attachments
Python script to run (268 bytes, text/plain)
2022-02-21 11:15 CET, Herman Viaene
Details
testdata for testexpat.py (693 bytes, text/xml)
2022-02-21 11:16 CET, Herman Viaene
Details

Description Thomas Backlund 2022-02-19 20:30:42 CET
https://seclists.org/oss-sec/2022/q1/150


SRPM:
expat-2.2.10-1.3.mga8.src.rpm


i586:
expat-2.2.10-1.3.mga8.i586.rpm
libexpat1-2.2.10-1.3.mga8.i586.rpm
libexpat-devel-2.2.10-1.3.mga8.i586.rpm


x86_64:
expat-2.2.10-1.3.mga8.x86_64.rpm
lib64expat1-2.2.10-1.3.mga8.x86_64.rpm
lib64expat-devel-2.2.10-1.3.mga8.x86_64.rpm
Comment 1 Herman Viaene 2022-02-21 11:15:19 CET
MGA8-64 Plasma on Lenoovo B50 in Dutch
No installation issues.
Followed wiki python testexpat.py, I will upload the test files.
$ python testexpat.py
Tested OK

so good to go.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 2 Herman Viaene 2022-02-21 11:15:55 CET
Created attachment 13156 [details]
Python script to run
Comment 3 Herman Viaene 2022-02-21 11:16:41 CET
Created attachment 13157 [details]
testdata for testexpat.py
Comment 4 David Walser 2022-02-21 23:47:01 CET
Ubuntu has issued an advisory for two of these issues today (February 21):
https://ubuntu.com/security/notices/USN-5288-1
Comment 5 Thomas Andrews 2022-02-22 04:21:25 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-02-22 20:34:19 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 6 Mageia Robot 2022-02-22 21:16:28 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0081.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 7 David Walser 2022-02-23 18:42:22 CET
Debian has issued an advisory for this on February 22:
https://www.debian.org/security/2022/dsa-5085

Note You need to log in before you can comment on or make changes to this bug.