Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:2508 - Security Advisory
Issued:
2020-06-10
Updated:
2020-06-10

RHSA-2020:2508 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: expat security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for expat is now available for Red Hat Enterprise Linux 7.7 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Expat is a C library for parsing XML documents.

Security Fix(es):

  • expat: Integer overflow leading to buffer overflow in XML_GetBuffer() (CVE-2015-2716)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing the updated packages, applications using the Expat library must be restarted for the update to take effect.

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 7.7 x86_64
  • Red Hat Enterprise Linux Server - AUS 7.7 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 7.7 s390x
  • Red Hat Enterprise Linux for Power, big endian - Extended Update Support 7.7 ppc64
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 7.7 ppc64le
  • Red Hat Enterprise Linux Server - TUS 7.7 x86_64
  • Red Hat Enterprise Linux EUS Compute Node 7.7 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 7.7 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 7.7 x86_64

Fixes

  • BZ - 1220607 - CVE-2015-2716 expat: Integer overflow leading to buffer overflow in XML_GetBuffer()

CVEs

  • CVE-2015-2716

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
x86_64
expat-2.1.0-11.el7_7.i686.rpm SHA-256: b6c8748a23088d35a9146ab2822154d6d1c498843c04fbc6d9d647ca17704678
expat-2.1.0-11.el7_7.x86_64.rpm SHA-256: d63379d8dfa5f2fcf9f459cdf0fde62c241fe710e0071b637a7873604b2d9a4d
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-devel-2.1.0-11.el7_7.i686.rpm SHA-256: bccc0cab40a9bd77781b320439f1b0e30b45e67f4c14ab0d8dfe2083ee757572
expat-devel-2.1.0-11.el7_7.x86_64.rpm SHA-256: 8e4f5a10dea2114af66451be06ce25d9950bfbc5faca89a74f3ec1a6e2d063bb
expat-static-2.1.0-11.el7_7.i686.rpm SHA-256: 9859e4267e8ad8d7a176912c41dd48ddc3a65d1a3316026c56e760bd1f37c81f
expat-static-2.1.0-11.el7_7.x86_64.rpm SHA-256: a768a5de94262268d22e819cc7e0e1cb06dbc7a4457383ec1805b063ba908634

Red Hat Enterprise Linux Server - AUS 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
x86_64
expat-2.1.0-11.el7_7.i686.rpm SHA-256: b6c8748a23088d35a9146ab2822154d6d1c498843c04fbc6d9d647ca17704678
expat-2.1.0-11.el7_7.x86_64.rpm SHA-256: d63379d8dfa5f2fcf9f459cdf0fde62c241fe710e0071b637a7873604b2d9a4d
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-devel-2.1.0-11.el7_7.i686.rpm SHA-256: bccc0cab40a9bd77781b320439f1b0e30b45e67f4c14ab0d8dfe2083ee757572
expat-devel-2.1.0-11.el7_7.x86_64.rpm SHA-256: 8e4f5a10dea2114af66451be06ce25d9950bfbc5faca89a74f3ec1a6e2d063bb
expat-static-2.1.0-11.el7_7.i686.rpm SHA-256: 9859e4267e8ad8d7a176912c41dd48ddc3a65d1a3316026c56e760bd1f37c81f
expat-static-2.1.0-11.el7_7.x86_64.rpm SHA-256: a768a5de94262268d22e819cc7e0e1cb06dbc7a4457383ec1805b063ba908634

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
s390x
expat-2.1.0-11.el7_7.s390.rpm SHA-256: a213de17f6a7fb837e55d23d7827278e7abf3cdc5e8674252d4e71d85eefe31c
expat-2.1.0-11.el7_7.s390x.rpm SHA-256: b6b1f6e0a196679de0393c7afd870bd935cbedc96f113a93f1b21189be0804b9
expat-debuginfo-2.1.0-11.el7_7.s390.rpm SHA-256: 2fb81ebcc667b0e4d206e56cf6e7796bd1a83cb3db9a4e870b548e7b9bd37e09
expat-debuginfo-2.1.0-11.el7_7.s390.rpm SHA-256: 2fb81ebcc667b0e4d206e56cf6e7796bd1a83cb3db9a4e870b548e7b9bd37e09
expat-debuginfo-2.1.0-11.el7_7.s390x.rpm SHA-256: 1abe7df4107172dba81abc54b0eed7ee7220f981265f04dea21218a29bdfdb0f
expat-debuginfo-2.1.0-11.el7_7.s390x.rpm SHA-256: 1abe7df4107172dba81abc54b0eed7ee7220f981265f04dea21218a29bdfdb0f
expat-devel-2.1.0-11.el7_7.s390.rpm SHA-256: f7288b38cad8cf5f591c82a2601d00fe33deb82956477fd19b46d9a92c4f6e8b
expat-devel-2.1.0-11.el7_7.s390x.rpm SHA-256: 0e3bace11ee303276de677e816e37a4704e9c6201e33588bbe8c0c719927c3ce
expat-static-2.1.0-11.el7_7.s390.rpm SHA-256: 6cc9109a853b496e6a3213946917f663bc2db71c44692344bbdb0871c5d2d049
expat-static-2.1.0-11.el7_7.s390x.rpm SHA-256: 0353a17b95b593fdabe7b14c7e665485dfda3a59baa957bc404a8aa6e17f9c34

Red Hat Enterprise Linux for Power, big endian - Extended Update Support 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
ppc64
expat-2.1.0-11.el7_7.ppc.rpm SHA-256: 9cb185736a27bba78588f6de9748c37d2d2f14af154b5ff5c403a6db5f47df6e
expat-2.1.0-11.el7_7.ppc64.rpm SHA-256: 0704719ef36e27051828630c32dcd572609d167c1a9e51ef89eb6c744578d123
expat-debuginfo-2.1.0-11.el7_7.ppc.rpm SHA-256: 377bd26bf26b0a8d3071296f5b130cd7f635df3afee6e20e6b272789d522be2c
expat-debuginfo-2.1.0-11.el7_7.ppc.rpm SHA-256: 377bd26bf26b0a8d3071296f5b130cd7f635df3afee6e20e6b272789d522be2c
expat-debuginfo-2.1.0-11.el7_7.ppc64.rpm SHA-256: 64f303dae3937505b0e85236402546a8d8698f01c1aec3c1a2ce41867d040c3d
expat-debuginfo-2.1.0-11.el7_7.ppc64.rpm SHA-256: 64f303dae3937505b0e85236402546a8d8698f01c1aec3c1a2ce41867d040c3d
expat-devel-2.1.0-11.el7_7.ppc.rpm SHA-256: 13d67e5c4adc85a463c893e9966f5db051d3439ebb0fc0004ed192f01d4fcadd
expat-devel-2.1.0-11.el7_7.ppc64.rpm SHA-256: eebfb884cf125d1185dcab34ccb5b4235bf7dfa291147cdfd584e3cbc925b06f
expat-static-2.1.0-11.el7_7.ppc.rpm SHA-256: 401dde8399d65f97835b4d841f5a635f67a744147ccdebc038b51fee87ffc380
expat-static-2.1.0-11.el7_7.ppc64.rpm SHA-256: 1c090cce6c8bdca8c02b69b14033673655bc45b635de079d3f439efb265da39a

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
ppc64le
expat-2.1.0-11.el7_7.ppc64le.rpm SHA-256: 02af69cd95243c343d4e9854933e490986bb4aa340f3ffcfba964aa434bd155d
expat-debuginfo-2.1.0-11.el7_7.ppc64le.rpm SHA-256: 53d2efc9a35b1b56697d84933034d94abeaa8e12417dbf46ccc1400163b21cb6
expat-debuginfo-2.1.0-11.el7_7.ppc64le.rpm SHA-256: 53d2efc9a35b1b56697d84933034d94abeaa8e12417dbf46ccc1400163b21cb6
expat-devel-2.1.0-11.el7_7.ppc64le.rpm SHA-256: 3c278ac00f3f9931715efb613ecc63a34b1a7ecf1ff0720f2249cc60800c19c5
expat-static-2.1.0-11.el7_7.ppc64le.rpm SHA-256: add754e3a4531d17528410659cc5d1d158adbd5aeecdc4ec50397b5611b0083e

Red Hat Enterprise Linux Server - TUS 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
x86_64
expat-2.1.0-11.el7_7.i686.rpm SHA-256: b6c8748a23088d35a9146ab2822154d6d1c498843c04fbc6d9d647ca17704678
expat-2.1.0-11.el7_7.x86_64.rpm SHA-256: d63379d8dfa5f2fcf9f459cdf0fde62c241fe710e0071b637a7873604b2d9a4d
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-devel-2.1.0-11.el7_7.i686.rpm SHA-256: bccc0cab40a9bd77781b320439f1b0e30b45e67f4c14ab0d8dfe2083ee757572
expat-devel-2.1.0-11.el7_7.x86_64.rpm SHA-256: 8e4f5a10dea2114af66451be06ce25d9950bfbc5faca89a74f3ec1a6e2d063bb
expat-static-2.1.0-11.el7_7.i686.rpm SHA-256: 9859e4267e8ad8d7a176912c41dd48ddc3a65d1a3316026c56e760bd1f37c81f
expat-static-2.1.0-11.el7_7.x86_64.rpm SHA-256: a768a5de94262268d22e819cc7e0e1cb06dbc7a4457383ec1805b063ba908634

Red Hat Enterprise Linux EUS Compute Node 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
x86_64
expat-2.1.0-11.el7_7.i686.rpm SHA-256: b6c8748a23088d35a9146ab2822154d6d1c498843c04fbc6d9d647ca17704678
expat-2.1.0-11.el7_7.x86_64.rpm SHA-256: d63379d8dfa5f2fcf9f459cdf0fde62c241fe710e0071b637a7873604b2d9a4d
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-devel-2.1.0-11.el7_7.i686.rpm SHA-256: bccc0cab40a9bd77781b320439f1b0e30b45e67f4c14ab0d8dfe2083ee757572
expat-devel-2.1.0-11.el7_7.x86_64.rpm SHA-256: 8e4f5a10dea2114af66451be06ce25d9950bfbc5faca89a74f3ec1a6e2d063bb
expat-static-2.1.0-11.el7_7.i686.rpm SHA-256: 9859e4267e8ad8d7a176912c41dd48ddc3a65d1a3316026c56e760bd1f37c81f
expat-static-2.1.0-11.el7_7.x86_64.rpm SHA-256: a768a5de94262268d22e819cc7e0e1cb06dbc7a4457383ec1805b063ba908634

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
ppc64le
expat-2.1.0-11.el7_7.ppc64le.rpm SHA-256: 02af69cd95243c343d4e9854933e490986bb4aa340f3ffcfba964aa434bd155d
expat-debuginfo-2.1.0-11.el7_7.ppc64le.rpm SHA-256: 53d2efc9a35b1b56697d84933034d94abeaa8e12417dbf46ccc1400163b21cb6
expat-debuginfo-2.1.0-11.el7_7.ppc64le.rpm SHA-256: 53d2efc9a35b1b56697d84933034d94abeaa8e12417dbf46ccc1400163b21cb6
expat-devel-2.1.0-11.el7_7.ppc64le.rpm SHA-256: 3c278ac00f3f9931715efb613ecc63a34b1a7ecf1ff0720f2249cc60800c19c5
expat-static-2.1.0-11.el7_7.ppc64le.rpm SHA-256: add754e3a4531d17528410659cc5d1d158adbd5aeecdc4ec50397b5611b0083e

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 7.7

SRPM
expat-2.1.0-11.el7_7.src.rpm SHA-256: f3dacb72a27947e8143eacf5ce02266dfb58e839dcf86782363cd35a7b1e7d33
x86_64
expat-2.1.0-11.el7_7.i686.rpm SHA-256: b6c8748a23088d35a9146ab2822154d6d1c498843c04fbc6d9d647ca17704678
expat-2.1.0-11.el7_7.x86_64.rpm SHA-256: d63379d8dfa5f2fcf9f459cdf0fde62c241fe710e0071b637a7873604b2d9a4d
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.i686.rpm SHA-256: 6d149b1cd1c3c32d64b94ad319014d51b13e11cf67ca47f7dbd07a89b0ab49e7
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-debuginfo-2.1.0-11.el7_7.x86_64.rpm SHA-256: d65c0f7a3fa1feea5f1ce9e7b30f75bae3fc93ae16d623aadb352d3c483a2193
expat-devel-2.1.0-11.el7_7.i686.rpm SHA-256: bccc0cab40a9bd77781b320439f1b0e30b45e67f4c14ab0d8dfe2083ee757572
expat-devel-2.1.0-11.el7_7.x86_64.rpm SHA-256: 8e4f5a10dea2114af66451be06ce25d9950bfbc5faca89a74f3ec1a6e2d063bb
expat-static-2.1.0-11.el7_7.i686.rpm SHA-256: 9859e4267e8ad8d7a176912c41dd48ddc3a65d1a3316026c56e760bd1f37c81f
expat-static-2.1.0-11.el7_7.x86_64.rpm SHA-256: a768a5de94262268d22e819cc7e0e1cb06dbc7a4457383ec1805b063ba908634

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility