ALAS-2016-775

Related Vulnerabilities: CVE-2016-0718  

CVE-2016-0718: Out-of-bounds read flawAn out-of-bounds read flaw was found in the way Expat processed certain input.A remote attacker could send specially crafted XML that, when parsed by anapplication using the Expat library, would cause that application to crash or,possibly, execute arbitrary code with the permission of the user running theapplication.

ALAS-2016-775


Amazon Linux AMI Security Advisory: ALAS-2016-775
Advisory Release Date: 2016-12-15 00:38 Pacific
Advisory Updated Date: 2016-12-15 23:51 Pacific
Severity: Medium

Issue Overview:

CVE-2016-0718: Out-of-bounds read flaw
An out-of-bounds read flaw was found in the way Expat processed certain input.
A remote attacker could send specially crafted XML that, when parsed by an
application using the Expat library, would cause that application to crash or,
possibly, execute arbitrary code with the permission of the user running the
application.


Affected Packages:

expat


Issue Correction:
Run yum update expat to update your system.

New Packages:
i686:
    expat-2.1.0-10.21.amzn1.i686
    expat-devel-2.1.0-10.21.amzn1.i686
    expat-debuginfo-2.1.0-10.21.amzn1.i686

src:
    expat-2.1.0-10.21.amzn1.src

x86_64:
    expat-debuginfo-2.1.0-10.21.amzn1.x86_64
    expat-devel-2.1.0-10.21.amzn1.x86_64
    expat-2.1.0-10.21.amzn1.x86_64