{"id":"CLSA-2024-1726163202","summary":"expat: Fix of 3 CVEs","details":"- The release version was raised because it corresponds to version 13\n- CVE-2024-45490: reject negative len for XML_ParseBuffer to prevent\n  improper restriction of XML External Entity Reference\n- CVE-2024-45491: prevent integer overflow in dtdCopy\n- CVE-2024-45492: prevent integer overflow in nextScaffoldPart","modified":"2026-06-01T00:32:55.665071692Z","published":"2024-09-12T17:46:46Z","upstream":["CVE-2024-45490","CVE-2024-45491","CVE-2024-45492"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/centos8stream-els/CLSA-2024-1726163202.html"}],"affected":[{"package":{"name":"expat","ecosystem":"TuxCare:CentOS-Stream:8","purl":"pkg:rpm/tuxcare/expat?distro=centos-stream-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.5-13.el8.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2024-1726163202.json"}},{"package":{"name":"expat-devel","ecosystem":"TuxCare:CentOS-Stream:8","purl":"pkg:rpm/tuxcare/expat-devel?distro=centos-stream-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.5-13.el8.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2024-1726163202.json"}},{"package":{"name":"expat-static","ecosystem":"TuxCare:CentOS-Stream:8","purl":"pkg:rpm/tuxcare/expat-static?distro=centos-stream-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.5-13.el8.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2024-1726163202.json"}}],"schema_version":"1.7.5"}