An infinite loop vulnerability due to malformed XML in external entity was found in entityValueInitProcessor function affecting versions of Expat 2.2.0 and earlier. Upstream patch: https://github.com/libexpat/libexpat/commit/c4bf96bb51dd2a1b0e185374362ee136fe2c9d7f External References: https://libexpat.github.io/doc/cve-2017-9233/
Created compat-expat1 tracking bugs for this issue: Affects: fedora-all [bug 1462732] Created expat tracking bugs for this issue: Affects: fedora-all [bug 1462735] Created expat21 tracking bugs for this issue: Affects: epel-all [bug 1462734] Created mingw-expat tracking bugs for this issue: Affects: epel-7 [bug 1462731] Affects: fedora-all [bug 1462733]
Mitigation: Do not parse untrusted arbitrary XML data using the expat package.