[FFe] Sync expat 2.4.1-1 (main) from Debian experimental (main)

Bug #1943133 reported by Rico Tzschichholz
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
expat (Ubuntu)
Fix Released
High
Unassigned

Bug Description

Please sync expat 2.4.1-1 (main) from Debian experimental (main)

https://github.com/libexpat/libexpat/blob/R_2_4_1/expat/Changes

CVE-2013-0340
https://github.com/libexpat/libexpat/pull/466/files

Changelog entries since current impish version 2.3.0-1:

expat (2.4.1-1) experimental; urgency=high

  * New upstream release:
    - fix CVE-2013-0340: protect against billion laughs attacks
      (denial-of-service; flavors targeting CPU time or RAM or both,
      leveraging general entities or parameter entities or both).
  * Update libexpat1 symbols.

 -- Laszlo Boszormenyi (GCS) <email address hidden> Mon, 24 May 2021 10:14:11 +0200

CVE References

Changed in expat (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Brian Murray (brian-murray) wrote :

Per our discussion in IRC given where we are in the release cycle this would require a Feature Freeze Exception.

description: updated
description: updated
Revision history for this message
Rico Tzschichholz (ricotz) wrote :

This has quite an impact with 264 reverse-depends, so does this security issue.

Revision history for this message
Rico Tzschichholz (ricotz) wrote :
Revision history for this message
Rico Tzschichholz (ricotz) wrote :
Revision history for this message
Rico Tzschichholz (ricotz) wrote :
summary: - Sync expat 2.4.1-1 (main) from Debian experimental (main)
+ [FFe] Sync expat 2.4.1-1 (main) from Debian experimental (main)
description: updated
Changed in expat (Ubuntu):
importance: Wishlist → High
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Ok, looking at the upstream changelog, I don't see any feature braking changes. One thing I'm worried about is the timing and the huge list of reverse-depends. This is not changing the SONAME or starting a transition, right? Asking since the CVE fix seems to actually be quite involving. And I wouldn't want us to get too much work right before Beta.

Changed in expat (Ubuntu):
status: New → Incomplete
Revision history for this message
Rico Tzschichholz (ricotz) wrote :

Thank you for taking a look.

There is *no* SONAME bump, ABI break or such. The newly introduced API is part of the CVE fix.

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Ok, hope we'll be able to get this migrating soon, since there might be quite a lot of ADT tests started from this one. Please be sure to shepherd it into the release pocket ASAP! +1

Changed in expat (Ubuntu):
status: Incomplete → Triaged
Revision history for this message
Sebastien Bacher (seb128) wrote :

This bug was fixed in the package expat - 2.4.1-2
Sponsored for Rico Tzschichholz (ricotz)

---------------
expat (2.4.1-2) unstable; urgency=medium

  * Upload to Sid.

 -- Laszlo Boszormenyi (GCS) <email address hidden> Thu, 09 Sep 2021 21:26:21 +0200

expat (2.4.1-1) experimental; urgency=high

  * New upstream release:
    - fix CVE-2013-0340: protect against billion laughs attacks
      (denial-of-service; flavors targeting CPU time or RAM or both,
      leveraging general entities or parameter entities or both).
  * Update libexpat1 symbols.

 -- Laszlo Boszormenyi (GCS) <email address hidden> Mon, 24 May 2021 10:14:11 +0200

Changed in expat (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.