The manufacturer Canonical has not yet set up its devicebase profile. Content such as updates, compatibilities and support may only be maintained with a delay.
Update

USN-7199-1: xmltok library vulnerabilities

USN-7199-1: xmltok library vulnerabilities
13 January 2025

Several security issues were fixed in libxmltok.

Releases

  • Ubuntu 24.10
  • Ubuntu 24.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM

Packages
libxmltok - XML Parser Toolkit, runtime libraries

Details
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)

It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)

It was discovered that Expat, contained within the xmltok library,
incorrectly handled certain input, which could lead to an integer
overflow. If a user or application were tricked into opening a crafted XML
file, an attacker could possibly use this issue to cause a denial of
service. (CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)

Update instructions
The problem can be corrected by updating your system to the following package versions:

Ubuntu 24.10

  • libxmltok1t64 - 1.2-4.1ubuntu3.1
    Ubuntu 24.04
  • libxmltok1t64 - 1.2-4.1ubuntu2.24.0.4.1+esm2
    Available with Ubuntu Pro
    Ubuntu 22.04
  • libxmltok1 - 1.2-4ubuntu0.22.04.1~esm4
    Available with Ubuntu Pro
    Ubuntu 20.04
    libxmltok1 - 1.2-4ubuntu0.20.04.1~esm4
  • Available with Ubuntu Pro
    Ubuntu 18.04
  • libxmltok1 - 1.2-4ubuntu0.18.04.1~esm4
    Available with Ubuntu Pro
    In general, a standard system update will make all the necessary changes.
Version: 24.04 LTS Link
Receive Important Update Messages Stay tuned for upcoming Canonical Ubuntu Desktop updates

Was the content helpful to you?

Advertisement Advertise here?
Udemy IT certification ad