Synopsis
The remote Debian host is missing one or more security-related updates.
Description
The remote Debian 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4807 advisory.
- ------------------------------------------------------------------------- Debian LTS Advisory DLA-4807-1 [email protected] https://www.debian.org/lts/security/ Andrej Shadura October 01, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : expat Version : 2.5.0-1+deb12u4 CVE ID : CVE-2024-28757 CVE-2025-59375 CVE-2026-24515 CVE-2026-25210 CVE-2026-32776 CVE-2026-32777 CVE-2026-32778 CVE-2026-45186 CVE-2026-66046 CVE-2026-93990
Multiple vulnerabilities have been found in expat.
CVE-2024-28757
A crafted XML document could trigger an entity expansion attack (billion laughs attack) when handled by an isolated external parser created via XML_ExternalEntityParserCreate bypassing the protections that applied to the parser's main document.
CVE-2025-59375
Small documents could trigger very large dynamic memory allocations potentially resulting in a denial of service.
CVE-2026-24515
XML_ExternalEntityParserCreate did not copy the unknown encoding handler's user data to the new external parser, which could result in a dangling pointer being used by the subparser.
CVE-2026-25210
The doContent function did not properly detect an integer overflow while reallocating the tag buffer for a long tag name, potentially resulting in a heap-based buffer overflow.
CVE-2026-32776
A crafter XML document could trigger NULL pointer dereference with empty external parameter entity content resulting in a denial of service.
CVE-2026-32777
A crafted XML document could trigger an infinite loop while parsing DTD content in entityValueProcessor resulting in a denial of service.
CVE-2026-32778
A crafted XML document using a namespace prefix could trigger a NULL pointer dereference after an earlier ouf-of-memory condition.
CVE-2026-45186
The computational complexity of handling default attributes was quadratic in the number of distinct attribute names which allowed a moderately sized crafted XML input to cause a denial of service.
CVE-2026-66046
A crafted XML document with a large number of distinct attributes could trigger a denial of service due to an O(N^2) linear-time attribute lookup.
CVE-2026-93990
Expat did not validate that a UTF-16 high surrogate was followed by a low surrogate, which could result in malformed UTF-16 data (unpaired surrogated) being accepted.
For Debian 12 bookworm, these problems have been fixed in version 2.5.0-1+deb12u4.
We recommend that you upgrade your expat packages.
For the detailed security status of expat please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/expat
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Tenable has extracted the preceding description block directly from the Debian security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Upgrade the expat packages.
Plugin Details
File Name: debian_DLA-4807.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Threat Vector: CVSS:4.0/E:P
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:expat, p-cpe:/a:debian:debian_linux:libexpat1-dev, p-cpe:/a:debian:debian_linux:libexpat1-udeb, p-cpe:/a:debian:debian_linux:libexpat1
Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l
Exploit Ease: Exploits are available
Patch Publication Date: 10/1/2026
Vulnerability Publication Date: 12/12/2023
Reference Information
CVE: CVE-2024-28757, CVE-2025-59375, CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, CVE-2026-45186, CVE-2026-66046, CVE-2026-93990
IAVA: 2024-A-0192-S, 2026-A-0100-S, 2026-A-0451, 2026-A-0925-S, 2026-A-1045