RHSA-2023:0103: Moderate: expat security update
Expat is a C library for parsing XML documents.Security Fix(es): expat: use-after free caused by overeager destruction of a shared DTD in XMLExternalEntityParserCreate (CVE-2022-43680)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0103?
RHSA-2023:0103 has been classified as a moderate severity vulnerability.
How do I fix RHSA-2023:0103?
To fix RHSA-2023:0103, update the expat package to version 2.2.5-10.el8_7.1 or later.
What does the vulnerability RHSA-2023:0103 affect?
RHSA-2023:0103 affects the expat C library, specifically versions below 2.2.5-10.el8_7.1.
What are the implications of the RHSA-2023:0103 vulnerability?
The implications of RHSA-2023:0103 include potential exploitation through a use-after-free condition leading to memory corruption.
Is there a specific package I need to update for RHSA-2023:0103?
Yes, you need to update the expat package along with its related packages like expat-debuginfo, expat-devel, and expat-debugsource.