Vulnerability Bulletins

DSA-3582 expat - security update

   
Affected software Debian
 
Gustavo Grieco discovered that Expat, an XML parsing C library, does notproperly handle certain kinds of malformed input documents, resulting inbuffer overflows during processing and error reporting. A remoteattacker can take advantage of this flaw to cause an application usingthe Expat library to crash, or potentially, to execute arbitrary codewith the privileges of the user running the application.

More info:

https://www.debian.org/security/2016/dsa-3582