Debian has issued an advisory on October 30: https://www.debian.org/security/2022/dsa-5266 The issue is fixed upstream in 2.5.0. We may have to patch Firefox and Thunderbird too (can wait until next update). Mageia 8 is also affected.
Whiteboard: (none) => MGA8TOOStatus comment: (none) => Fixed upstream in 2.5.0Assignee: bugsquad => nicolas.salguero
Suggested advisory: ======================== The updated packages fix a security vulnerability: In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. (CVE-2022-43680) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43680 https://www.debian.org/security/2022/dsa-5266 ======================== Updated packages in core/updates_testing: ======================== expat-2.2.10-1.6.mga8 lib(64)expat1-2.2.10-1.6.mga8 lib(64)expat-devel-2.2.10-1.6.mga8 from SRPM: expat-2.2.10-1.6.mga8.src.rpm
Status comment: Fixed upstream in 2.5.0 => (none)Status: NEW => ASSIGNEDWhiteboard: MGA8TOO => (none)CC: (none) => nicolas.salgueroCVE: (none) => CVE-2022-43680Assignee: nicolas.salguero => qa-bugsVersion: Cauldron => 8Source RPM: expat-2.4.9-1.mga9.src.rpm => expat-2.2.10-1.5.mga8.src.rpm
MGA8-64 MATE on Acer Aspire 5253 No installation issues. Followed wiki-procedure (I will upload the files used) $ cd Documents/expat/ $ ls testdata.xml testexpat.py $ python testexpat.py Tested OK and to be sure $ python3 testexpat.py Tested OK And as in the wiki $ xmlwf /etc/xml/catalog $ xmlwf /etc/passwd /etc/passwd:1:16: not well-formed (invalid token) Looks good to me.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA8-64-OK
Created attachment 13471 [details] python script
Created attachment 13472 [details] testdata
Validating. Advisory in Comment 2.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
Keywords: (none) => advisoryCC: (none) => davidwhodgins
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0409.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED