diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 6ddca139888..6ad993fa942 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,36 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + expat2 -- Fix extraction of namespace prefixes from XML names + + + expat + 2.2.7 + + + + +

expat project reports:

+
+

+ XML names with multiple colons could end up in the + wrong namespace, and take a high amount of RAM and CPU + resources while processing, opening the door to + use for denial-of-service attacks +

+
+ +
+ + https://github.com/libexpat/libexpat/blob/R_2_2_7/expat/Changes + + + 2019-06-19 + 2019-09-16 + +
+ curl -- multiple vulnerabilities @@ -124,7 +154,7 @@ Notes: openssl - 1.0.2t + 1.0.2t,1 openssl111