expat 2.4.7-1ubuntu0.2 source package in Ubuntu


expat (2.4.7-1ubuntu0.2) jammy-security; urgency=medium

  * SECURITY UPDATE: use-after-free
    - debian/patches/CVE-2022-43680-1.patch: adds tests to cover
      DTD destruction in XML_ExternalEntityParserCreate in
    - debian/patches/CVE-2022-43680-2.patch: fix overeager DTD
      destruction in XML_ExternalEntityParserCreate in
    - CVE-2022-43680

 -- David Fernandez Gonzalez <email address hidden>  Fri, 18 Nov 2022 12:21:42 +0100

Upload details

Uploaded by:
David Fernandez Gonzalez
Uploaded to:
Original maintainer:
Ubuntu Developers
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section


File Size SHA-256 Checksum
expat_2.4.7.orig.tar.gz 7.9 MiB ddc1111651cdd4095b67c9d9ed46babfb8fb64843d89ff785399f5739b84867b
expat_2.4.7-1ubuntu0.2.debian.tar.xz 14.5 KiB 7b61a600a00bf9039efccee6cc28d7a49f5092aea8921883c06ef159b44c746d
expat_2.4.7-1ubuntu0.2.dsc 2.1 KiB effd2139b249bbe05b8770d07992827d354dc5e11757e7700d08a0b41c7e907d

View changes file

Binary packages built by this source

expat: XML parsing C library - example application

 This package contains xmlwf, an example application of expat, the C
 library for parsing XML. The arguments to xmlwf are one or more
 files which are each to be checked for XML well-formedness.

expat-dbgsym: debug symbols for expat
libexpat1: XML parsing C library - runtime library

 This package contains the runtime, shared library of expat, the C
 library for parsing XML. Expat is a stream-oriented parser in
 which an application registers handlers for things the parser
 might find in the XML document (like start tags).

libexpat1-dbgsym: debug symbols for libexpat1
libexpat1-dev: XML parsing C library - development kit

 This package contains the header file and development libraries of
 expat, the C library for parsing XML. Expat is a stream oriented XML
 parser. This means that you register handlers with the parser prior
 to starting the parse. These handlers are called when the parser
 discovers the associated structures in the document being parsed. A
 start tag is an example of the kind of structures for which you may
 register handlers.