It was discovered that Expat did not properly handle its internal state when attempting to resume an unstarted parser. An attacker could use this issue to cause a denial of service (application crash).
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "expat",
"binary_version": "2.1.0-4ubuntu1.4+esm10"
},
{
"binary_name": "lib64expat1",
"binary_version": "2.1.0-4ubuntu1.4+esm10"
},
{
"binary_name": "lib64expat1-dev",
"binary_version": "2.1.0-4ubuntu1.4+esm10"
},
{
"binary_name": "libexpat1",
"binary_version": "2.1.0-4ubuntu1.4+esm10"
},
{
"binary_name": "libexpat1-dev",
"binary_version": "2.1.0-4ubuntu1.4+esm10"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "expat",
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10"
},
{
"binary_name": "lib64expat1",
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10"
},
{
"binary_name": "lib64expat1-dev",
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10"
},
{
"binary_name": "libexpat1",
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10"
},
{
"binary_name": "libexpat1-dev",
"binary_version": "2.1.0-7ubuntu0.16.04.5+esm10"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "expat",
"binary_version": "2.2.5-3ubuntu0.9+esm2"
},
{
"binary_name": "libexpat1",
"binary_version": "2.2.5-3ubuntu0.9+esm2"
},
{
"binary_name": "libexpat1-dev",
"binary_version": "2.2.5-3ubuntu0.9+esm2"
}
]
}