- Joined
- Nov 17, 2020
- Messages
- 6
- Reaction score
- 0
Hey,
Not sure if this is the right place - our vulnerability scanner has picked up that our 3CX server (official ISO installation) is running a vulnerable version of libexpat1. 3CX has pinned the previous version, so an apt upgrade won't update it. I think we're running the latest version of everything.
The CVE https://www.debian.org/security/2022/dsa-5073
Our version: 18.0 update 3 (Build 314)
Excerpt from /etc/apt/preferences.d/3cxpbx:
Package: libexpat1
Pin: version 2.2.6-2+deb10u1
Cheers
Not sure if this is the right place - our vulnerability scanner has picked up that our 3CX server (official ISO installation) is running a vulnerable version of libexpat1. 3CX has pinned the previous version, so an apt upgrade won't update it. I think we're running the latest version of everything.
The CVE https://www.debian.org/security/2022/dsa-5073
Our version: 18.0 update 3 (Build 314)
Excerpt from /etc/apt/preferences.d/3cxpbx:
Package: libexpat1
Pin: version 2.2.6-2+deb10u1
Cheers