DSA-4530 expat – security update
It was discovered that Expat, an XML parsing C library, did not properlyhandled internal entities closing the doctype, potentially resulting indenial of service or information disclosure if a malformed XML file isprocessed.
More info:
https://www.debian.org/security/2019/dsa-4530