Fedora Account System
Red Hat Associate
Red Hat Customer
An infinite loop vulnerability due to malformed XML in external entity was found in entityValueInitProcessor function affecting versions of Expat 2.2.0 and earlier. Upstream patch: https://github.com/libexpat/libexpat/commit/c4bf96bb51dd2a1b0e185374362ee136fe2c9d7f External References: https://libexpat.github.io/doc/cve-2017-9233/
Created compat-expat1 tracking bugs for this issue: Affects: fedora-all [bug 1462732] Created expat tracking bugs for this issue: Affects: fedora-all [bug 1462735] Created expat21 tracking bugs for this issue: Affects: epel-all [bug 1462734] Created mingw-expat tracking bugs for this issue: Affects: epel-7 [bug 1462731] Affects: fedora-all [bug 1462733]
Mitigation: Do not parse untrusted arbitrary XML data using the expat package.