Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 10 Buster DLA-3260-1 Critical: Node-Xmldom XML Parsing Issues

debian lts
Calendar Grey January 1, 2023
Dist Debian Esm H88
Update the static node-xmldom library to remediate vulnerabilities associated with XML handling in Debian environments.
It was discovered that node-xmldom, a standard XML DOM (Level2 CORE) implementation in pure javascript, processed ill-formed XML, which may result in bugs and security holes in dow...

Summary

CVE-2021-21366

xmldom versions 0.4.0 and older do not correctly preserve system
identifiers, FPIs or namespaces when repeatedly parsing and serializing
maliciously crafted documents. This may lead to unexpected syntactic
changes during XML processing in some downstream applications.

CVE-2022-39353

Mark Gollnick discovered that xmldom parses XML that is not well-formed
because it contains multiple top level elements, and adds all root nodes to
the `childNodes` collection of the `Document`, without reporting or throwing
any error. This breaks the assumption that there is only a single root node
in the tree, and may open security holes such as CVE-2022-39299 in
downstream applications.

For Debian 10 buster, these problems have been fixed in version
0.1.27+ds-1+deb10u2.

We recommend that you upgrade your node-xmldom packages.

For the detailed security status of node-xmldom please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: node-xmldom
Version: 0.1.27+ds-1+deb10u2
CVE ID: CVE-2021-21366 CVE-2022-39353
Debian Bug: 1024736

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here