{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [],
            "removed": [],
            "diff": [
                "libexpat1:s390x"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "libexpat1:s390x",
                "from_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.6.1-2build1",
                    "version": "2.6.1-2build1"
                },
                "to_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.6.1-2ubuntu0.1",
                    "version": "2.6.1-2ubuntu0.1"
                },
                "cves": [
                    {
                        "cve": "CVE-2024-45490",
                        "url": "https://ubuntu.com/security/CVE-2024-45490",
                        "cve_description": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.",
                        "cve_priority": "medium",
                        "cve_public_date": "2024-08-30 03:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2024-45491",
                        "url": "https://ubuntu.com/security/CVE-2024-45491",
                        "cve_description": "An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).",
                        "cve_priority": "medium",
                        "cve_public_date": "2024-08-30 03:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2024-45492",
                        "url": "https://ubuntu.com/security/CVE-2024-45492",
                        "cve_description": "An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).",
                        "cve_priority": "medium",
                        "cve_public_date": "2024-08-30 03:15:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-45490",
                                "url": "https://ubuntu.com/security/CVE-2024-45490",
                                "cve_description": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.",
                                "cve_priority": "medium",
                                "cve_public_date": "2024-08-30 03:15:00 UTC"
                            },
                            {
                                "cve": "CVE-2024-45491",
                                "url": "https://ubuntu.com/security/CVE-2024-45491",
                                "cve_description": "An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).",
                                "cve_priority": "medium",
                                "cve_public_date": "2024-08-30 03:15:00 UTC"
                            },
                            {
                                "cve": "CVE-2024-45492",
                                "url": "https://ubuntu.com/security/CVE-2024-45492",
                                "cve_description": "An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).",
                                "cve_priority": "medium",
                                "cve_public_date": "2024-08-30 03:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: invalid input length",
                            "    - CVE-2024-45490-*.patch: adds a check to the XML_ParseBuffer function of",
                            "      expat/lib/xmlparse.c to identify and error out if a negative length is",
                            "      provided.",
                            "    - CVE-2024-45490",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - CVE-2024-45491.patch: adds a check to the dtdCopy function of",
                            "      expat/lib/xmlparse.c to detect and prevent an integer overflow.",
                            "    - CVE-2024-45491",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - CVE-2024-45492.patch: adds a check to the nextScaffoldPart function of",
                            "      expat/lib/xmlparse.c to detect and prevent an integer overflow.",
                            "    - CVE-2024-45492",
                            ""
                        ],
                        "package": "expat",
                        "version": "2.6.1-2ubuntu0.1",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Ian Constantin <ian.constantin@canonical.com>",
                        "date": "Tue, 10 Sep 2024 13:17:43 +0300"
                    }
                ],
                "notes": null
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [],
        "snap": []
    },
    "removed": {
        "deb": [],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 24.04 noble image from release image serial 20240911 to 20240912",
    "from_series": "noble",
    "to_series": "noble",
    "from_serial": "20240911",
    "to_serial": "20240912",
    "from_manifest_filename": "release_manifest.previous",
    "to_manifest_filename": "manifest.current"
}