It was discovered that Expat did not properly handle its internal state when attempting to resume an unstarted parser. An attacker could use this issue to cause a denial of service (application crash).
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.1.0-4ubuntu1.4+esm10",
"binary_name": "expat"
},
{
"binary_version": "2.1.0-4ubuntu1.4+esm10",
"binary_name": "lib64expat1"
},
{
"binary_version": "2.1.0-4ubuntu1.4+esm10",
"binary_name": "lib64expat1-dev"
},
{
"binary_version": "2.1.0-4ubuntu1.4+esm10",
"binary_name": "libexpat1"
},
{
"binary_version": "2.1.0-4ubuntu1.4+esm10",
"binary_name": "libexpat1-dev"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10",
"binary_name": "expat"
},
{
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10",
"binary_name": "lib64expat1"
},
{
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10",
"binary_name": "lib64expat1-dev"
},
{
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10",
"binary_name": "libexpat1"
},
{
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10",
"binary_name": "libexpat1-dev"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.2.5-3ubuntu0.9+esm2",
"binary_name": "expat"
},
{
"binary_version": "2.2.5-3ubuntu0.9+esm2",
"binary_name": "libexpat1"
},
{
"binary_version": "2.2.5-3ubuntu0.9+esm2",
"binary_name": "libexpat1-dev"
}
]
}