Packages
- libxmltok - XML Parser Toolkit, runtime libraries
Details
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, contained within the xmltok library,
incorrectly...
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled certain input, which could lead to an integer
overflow. If a user or application were tricked into opening a crafted XML
file, an attacker could possibly use this issue to cause a denial of
service. (CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
24.10 oracular | libxmltok1t64 – 1.2-4.1ubuntu3.1 | ||
24.04 noble | libxmltok1t64 – 1.2-4.1ubuntu2.24.0.4.1+esm2 | ||
22.04 jammy | libxmltok1 – 1.2-4ubuntu0.22.04.1~esm4 | ||
20.04 focal | libxmltok1 – 1.2-4ubuntu0.20.04.1~esm4 | ||
18.04 bionic | libxmltok1 – 1.2-4ubuntu0.18.04.1~esm4 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
References
- CVE-2022-22827
- CVE-2022-22826
- CVE-2022-22825
- CVE-2022-22824
- CVE-2022-22823
- CVE-2022-22822
- CVE-2021-46143
- CVE-2019-15903
- CVE-2018-20843
- CVE-2016-4472
- CVE-2022-22827
- CVE-2022-22826
- CVE-2022-22825
- CVE-2022-22824
- CVE-2022-22823
- CVE-2022-22822
- CVE-2021-46143
- CVE-2019-15903
- CVE-2018-20843
- CVE-2016-4472
- CVE-2016-0718
- CVE-2015-1283
Related notices
- USN-5455-1
- USN-5288-1
- USN-4852-1
- USN-4772-1
- USN-4335-1
- USN-4202-1
- USN-4165-1
- USN-4132-2
- USN-4132-1
- USN-4040-1
- USN-5455-1
- USN-5288-1
- USN-4852-1
- USN-4772-1
- USN-4335-1
- USN-4202-1
- USN-4165-1
- USN-4132-2
- USN-4132-1
- USN-4040-1
- USN-4040-2
- USN-3044-1
- USN-3013-1
- USN-2983-1
- USN-2726-1
- USN-2677-1