[CLSA-2026:1777305047] expat: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-27 15:50:52 UTC
Description:
- CVE-2017-9233: Fix external entity infinite loop bug - CVE-2018-20843: Fix extraction of namespace prefix from XML name - CVE-2019-15903: Deny internal entities closing the doctype (heap overread)
Updated packages:
  • expat-2.0.1-13.el6_8.tuxcare.els8.i686.rpm
    sha:36970ccd45f1e9f835dec0d1f26202c2d442f73c42f046a270e3e8dc083895d3
  • expat-2.0.1-13.el6_8.tuxcare.els8.x86_64.rpm
    sha:43a5a9a5cc555370ca8126e721f7dcc72f72e02a782b292a317d193ce1693727
  • expat-devel-2.0.1-13.el6_8.tuxcare.els8.i686.rpm
    sha:879d31cece9695d71cae1c3d8ec598060d6c33317f712a5e546974b590983e1c
  • expat-devel-2.0.1-13.el6_8.tuxcare.els8.x86_64.rpm
    sha:21cd46ef198efd649d3ccc4efdd2e16f1c30c4e01e08cfcb1d8f291f6de2cc8e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.