Your submission was sent successfully! Close

CVE-2018-20843

Published: 24 June 2019

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).

Priority

Low

CVSS 3 base score: 7.5

Status

Package Release Status
apache2
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(code-not-compiled)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(code-not-compiled)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(code-not-compiled)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(code-not-compiled)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(code-not-compiled)
Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable
(code-not-compiled)
apr-util
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(code-not-compiled)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(code-not-compiled)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(code-not-compiled)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(code-not-compiled)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(code-not-compiled)
Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable
(code-not-compiled)
audacity
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(uses system expat)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(uses system expat)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

ayttm
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needs-triage)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

cableswig
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needs-triage)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

cadaver
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Needs triage

Ubuntu 21.04 (Hirsute Hippo) Needs triage

Ubuntu 20.04 LTS (Focal Fossa) Needs triage

Ubuntu 18.04 LTS (Bionic Beaver) Needs triage

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needs-triage)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

cmake
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(code-not-compiled)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(code-not-compiled)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(code-not-compiled)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(code-not-compiled)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(code-not-compiled)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

coin3
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Needed

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needed)
Ubuntu 14.04 ESM (Trusty Tahr) Needed

expat
Launchpad, Ubuntu, Debian
Upstream
Released (2.2.6-2)
Ubuntu 21.10 (Impish Indri)
Released (2.2.6-2)
Ubuntu 21.04 (Hirsute Hippo)
Released (2.2.6-2)
Ubuntu 20.04 LTS (Focal Fossa)
Released (2.2.6-2)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (2.2.5-3ubuntu0.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (2.1.0-7ubuntu0.16.04.4)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (2.1.0-4ubuntu1.4+esm1)
Patches:
Upstream: https://github.com/libexpat/libexpat/commit/11f8838bf99ea0a6f0b76f9760c43704d00c4ff6
firefox
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable

Ubuntu 21.04 (Hirsute Hippo) Not vulnerable

Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable

Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable

Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

gdcm
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(uses system expat)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(uses system expat)
Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable
(uses system expat)
ghostscript
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(code-not-compiled)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(code-not-compiled)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(code-not-compiled)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(code-not-compiled)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(code-not-compiled)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

insighttoolkit
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needs-triage)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

insighttoolkit4
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(uses system expat)
Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needed)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

kompozer
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

libparagui1.1
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

matanza
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Needs triage

Ubuntu 21.04 (Hirsute Hippo) Needs triage

Ubuntu 20.04 LTS (Focal Fossa) Needs triage

Ubuntu 18.04 LTS (Bionic Beaver) Needs triage

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needs-triage)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

poco
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(uses system expat)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(uses system expat)
Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable
(uses system expat)
simgear
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(uses system expat)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(uses system expat)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

sitecopy
Launchpad, Ubuntu, Debian
Upstream Not vulnerable
(uses system expat)
Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(uses system expat)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(uses system expat)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

smart
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(code-not-compiled)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(code-not-compiled)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

swish-e
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Needs triage

Ubuntu 21.04 (Hirsute Hippo) Needs triage

Ubuntu 20.04 LTS (Focal Fossa) Needs triage

Ubuntu 18.04 LTS (Bionic Beaver) Needs triage

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needs-triage)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

tdom
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(uses system expat)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(uses system expat)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

texlive-bin
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(code-not-compiled)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(code-not-compiled)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(code-not-compiled)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(code-not-compiled)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(code-not-compiled)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

thunderbird
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable

Ubuntu 21.04 (Hirsute Hippo) Not vulnerable

Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable

Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable

Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

vnc4
Launchpad, Ubuntu, Debian
Upstream Needed

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Needed

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needed)
Ubuntu 14.04 ESM (Trusty Tahr) Needed

vtk
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needed)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

wbxml2
Launchpad, Ubuntu, Debian
Upstream Not vulnerable
(uses system expat)
Ubuntu 21.10 (Impish Indri) Not vulnerable
(uses system expat)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(uses system expat)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(uses system expat)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(uses system expat)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(uses system expat)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

wxwidgets2.6
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

wxwidgets2.8
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Does not exist

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

xmlrpc-c
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Needs triage

Ubuntu 21.04 (Hirsute Hippo) Needs triage

Ubuntu 20.04 LTS (Focal Fossa) Needs triage

Ubuntu 18.04 LTS (Bionic Beaver) Needs triage

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needs-triage)
Ubuntu 14.04 ESM (Trusty Tahr) Needs triage