{"id":"CLSA-2022-1667412749","summary":"Fix CVE(s): CVE-2022-43680","details":"\n   * SECURITY UPDATE: Fix overeager DTD destruction\n     - debian/patches/CVE-2022-43680: Fix heap use-after-free after overeager\n       destruction of a shared DTD in function XML_ExternalEntityParserCreate\n       in out-of-memory situations\n     - CVE-2022-43680","modified":"2026-06-04T09:45:51.935017049Z","published":"2022-11-02T18:12:29Z","upstream":["CVE-2022-43680"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16-els/CLSA-2022-1667412749"}],"affected":[{"package":{"name":"expat","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/expat?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0-7ubuntu0.16.04.5+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1667412749.json"}},{"package":{"name":"libexpat1","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libexpat1?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0-7ubuntu0.16.04.5+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1667412749.json"}},{"package":{"name":"libexpat1-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libexpat1-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0-7ubuntu0.16.04.5+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1667412749.json"}}],"schema_version":"1.7.5"}