=========================================================================Ubuntu Security Notice USN-5638-3
November 23, 2022

expat vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM

Summary:

Expat could be made to crash or execute arbitrary code.

Software Description:
- expat: XML parsing C library

Details:

USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-43680)
This update also fixes a minor regression introduced in
Ubuntu 18.04 LTS.

We apologize for the inconvenience.

Original advisory details:

  Rhodri James discovered that Expat incorrectly handled memory when
  processing certain malformed XML files. An attacker could possibly
  use this issue to cause a crash or execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
   expat                           2.4.8-2ubuntu0.22.10.1
   libexpat1                       2.4.8-2ubuntu0.22.10.1

Ubuntu 22.04 LTS:
   expat                           2.4.7-1ubuntu0.2
   libexpat1                       2.4.7-1ubuntu0.2

Ubuntu 20.04 LTS:
   expat                           2.2.9-1ubuntu0.6
   libexpat1                       2.2.9-1ubuntu0.6

Ubuntu 18.04 LTS:
   expat                           2.2.5-3ubuntu0.9
   libexpat1                       2.2.5-3ubuntu0.9

Ubuntu 16.04 ESM:
   expat                           2.1.0-7ubuntu0.16.04.5+esm7
   lib64expat1                     2.1.0-7ubuntu0.16.04.5+esm7
   libexpat1                       2.1.0-7ubuntu0.16.04.5+esm7

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5638-3
   https://ubuntu.com/security/notices/USN-5638-1
   CVE-2022-43680

Package Information:
https://launchpad.net/ubuntu/+source/expat/2.4.8-2ubuntu0.22.10.1
   https://launchpad.net/ubuntu/+source/expat/2.4.7-1ubuntu0.2
   https://launchpad.net/ubuntu/+source/expat/2.2.9-1ubuntu0.6
   https://launchpad.net/ubuntu/+source/expat/2.2.5-3ubuntu0.9

Ubuntu 5638-3: Expat vulnerability

November 23, 2022
Expat could be made to crash or execute arbitrary code.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10:   expat                           2.4.8-2ubuntu0.22.10.1   libexpat1                       2.4.8-2ubuntu0.22.10.1 Ubuntu 22.04 LTS:   expat                           2.4.7-1ubuntu0.2   libexpat1                       2.4.7-1ubuntu0.2 Ubuntu 20.04 LTS:   expat                           2.2.9-1ubuntu0.6   libexpat1                       2.2.9-1ubuntu0.6 Ubuntu 18.04 LTS:   expat                           2.2.5-3ubuntu0.9   libexpat1                       2.2.5-3ubuntu0.9 Ubuntu 16.04 ESM:   expat                           2.1.0-7ubuntu0.16.04.5+esm7   lib64expat1                     2.1.0-7ubuntu0.16.04.5+esm7   libexpat1                       2.1.0-7ubuntu0.16.04.5+esm7 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-5638-3

  https://ubuntu.com/security/notices/USN-5638-1

  CVE-2022-43680

Severity
November 23, 2022

Package Information

https://launchpad.net/ubuntu/+source/expat/2.4.8-2ubuntu0.22.10.1   https://launchpad.net/ubuntu/+source/expat/2.4.7-1ubuntu0.2   https://launchpad.net/ubuntu/+source/expat/2.2.9-1ubuntu0.6   https://launchpad.net/ubuntu/+source/expat/2.2.5-3ubuntu0.9

Related News