Debian Package Tracker
Register | Log in
Subscribe

expat

XML parsing C library - example application

Choose email to subscribe with

general
  • source: expat (main)
  • version: 2.7.2-1
  • maintainer: Laszlo Boszormenyi (GCS) (DMD)
  • arch: any
  • std-ver: 4.7.2
  • VCS: unknown
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.2.10-2+deb11u5
  • o-o-sec: 2.2.10-2+deb11u7
  • oldstable: 2.5.0-1+deb12u1
  • old-sec: 2.5.0-1+deb12u1
  • stable: 2.7.1-2
  • testing: 2.7.2-1
  • unstable: 2.7.2-1
versioned links
  • 2.2.10-2+deb11u5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.2.10-2+deb11u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.5.0-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.7.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.7.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • expat
  • libexpat1
  • libexpat1-dev (2 bugs: 0, 2, 0, 0)
  • libexpat1-udeb
action needed
Problems while searching for a new upstream version high
uscan had problems while searching for a new upstream version:
more than one main upstream tarballs listed.
Created: 2024-09-05 Last update: 2025-09-19 09:31
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-59375: libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Created: 2025-09-15 Last update: 2025-09-19 03:30
2 security issues in bullseye high

There are 2 open security issues in bullseye.

1 important issue:
  • CVE-2025-59375: libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
1 ignored issue:
  • CVE-2024-8176: A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
Created: 2025-09-15 Last update: 2025-09-19 03:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2025-59375: libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Created: 2025-09-15 Last update: 2025-09-19 03:30
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2025-09-17 Last update: 2025-09-17 04:32
news
[rss feed]
  • [2025-09-19] expat 2.7.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-19] expat 2.7.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-16] Accepted expat 2.7.2-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-07-21] expat 2.7.1-2 MIGRATED to testing (Debian testing watch)
  • [2025-07-17] Accepted expat 2.7.1-2 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-05-31] Accepted expat 2.5.0-1+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Laszlo Boszormenyi)
  • [2025-04-30] Accepted expat 2.2.10-2+deb11u7 (source) into oldstable-security (Thorsten Alteholz)
  • [2025-03-30] expat 2.7.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-27] Accepted expat 2.7.1-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-03-14] Accepted expat 2.7.0-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-11-14] expat 2.6.4-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-08] Accepted expat 2.6.4-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-10-31] expat 2.6.3-2 MIGRATED to testing (Debian testing watch)
  • [2024-10-27] Accepted expat 2.6.3-2 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-09-19] Accepted expat 2.2.10-2+deb11u6 (source) into oldstable-security (Guilhem Moulin)
  • [2024-09-18] Accepted expat 2.5.0-1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Laszlo Boszormenyi)
  • [2024-09-17] Accepted expat 2.5.0-1+deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Laszlo Boszormenyi)
  • [2024-09-10] expat 2.6.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-04] Accepted expat 2.6.3-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-09-02] expat 2.6.2-2 MIGRATED to testing (Debian testing watch)
  • [2024-08-31] Accepted expat 2.6.2-2 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-04-19] expat 2.6.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-06] Accepted expat 2.2.6-2+deb10u7 (source) into oldoldstable (Tobias Frost)
  • [2024-03-13] Accepted expat 2.6.2-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-03-10] Accepted expat 2.6.1-2 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-03-06] Accepted expat 2.6.1-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-02-06] Accepted expat 2.6.0-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2023-06-25] expat 2.5.0-2 MIGRATED to testing (Debian testing watch)
  • [2023-06-14] Accepted expat 2.5.0-2 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2022-11-05] Accepted expat 2.2.10-2+deb11u5 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.7.1-2
  • 7 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing