Debian Patches

Status for expat/2.5.0-1+deb12u2

Patch Description Author Forwarded Bugs Origin Last update
fix-expat-noconfig.patch libexpat.so.X.Y.Z is installed in /lib/${DEB_HOST_MULTIARCH} instead of /usr/lib/${DEB_HOST_MULTIARCH}, thus the path of the shared library
is not relative to the location of this cmake file (Closes: #995907)
Andrius Merkys <merkys@debian.org> not-needed
fix-expat-cmake.patch no
CVE-2024-45490.patch [PATCH 1/3] lib: Reject negative len for XML_ParseBuffer
Reported by TaiYou
Sebastian Pipping <sebastian@pipping.org> no 2024-08-19
CVE-2024-45491.patch [PATCH] lib: Detect integer overflow in dtdCopy
Reported by TaiYou
Sebastian Pipping <sebastian@pipping.org> no 2024-08-19
CVE-2024-45492.patch [PATCH] lib: Detect integer overflow in function nextScaffoldPart
Reported by TaiYou
Sebastian Pipping <sebastian@pipping.org> no 2024-08-19
expat-2.5.0-CVE-2023-52425.patch commit 678a2f7efcaaa977886e055613f2332615aef82c

Fix CVE-2023-52425

diff --git a/expat/Makefile.am b/expat/Makefile.am
index 37ae373..cd0117f 100644
Tomas Korbar <tkorbar@redhat.com> no 2024-02-13
expat-2.5.0-CVE-2024-50602.patch commit 38905b99bb78a6a691ed8358f30030116783656c

Fix CVE-2024-50602

See https://github.com/libexpat/libexpat/pull/915

diff --git a/expat/lib/expat.h b/expat/lib/expat.h
index 842dd70..69b0ba1 100644
Tomas Korbar <tkorbar@redhat.com> no 2024-11-07
expat-2.5.0-CVE-2024-8176.patch commit c0de4903900004dd3ca91f246e5f6489a49a132b

Fix CVE-2024-8176

diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
index 8b2af91..d68d2c8 100644
Tomas Korbar <tkorbar@redhat.com> no 2025-03-24

All known versions for source package 'expat'

Links