{"id":"MGASA-2026-0173","summary":"Updated xmlrpc-c packages fix security vulnerabilities","details":"This update fixes the vulnerabilities by no longer building with the\nvulnerable bundled libexpat version.\n","modified":"2026-06-05T17:45:08.885986445Z","published":"2026-06-05T17:37:45Z","upstream":["CVE-2022-25236","CVE-2022-25313","CVE-2022-25314","CVE-2022-25315","CVE-2022-40674","CVE-2022-43680"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0173.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31123"}],"affected":[{"package":{"name":"xmlrpc-c","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/xmlrpc-c?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.51.08-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0173.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}