Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Fedora 36: FEDORA-2022-aeafd24818 Critical: xmlsec1 Integer Overflows

fedora
Calendar Grey October 25, 2022
Dist Fedora Esm H88
An update for xmlsec1 has been released for Fedora 36, resolving two significant vulnerabilities. It's crucial to upgrade to the latest version to ensure the security of your system.
Update to 2.10.3 * Fix CVE-2022-40303 * Fix CVE-2022-40304

Summary

XML Security Library is a C library based on LibXML2 and OpenSSL.

The library was created with a goal to support major XML security

standards "XML Digital Signature" and "XML Encryption".

Update to 2.10.3 * Fix CVE-2022-40303 * Fix CVE-2022-40304

* Mon Oct 24 2022 David King - 1.2.33-3

- Rebuild against libxml2 (#2136800)

[ 1 ] Bug #2119077 - libxml2-2.10.2 is available

https://bugzilla.redhat.com/show_bug.cgi?id=2119077

[ 2 ] Bug #2136274 - CVE-2022-40303 libxml2: integer overflows with XML_PARSE_HUGE [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2136274

[ 3 ] Bug #2136293 - CVE-2022-40304 libxml2: dict corruption caused by entity reference cycles [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2136293

[ 4 ] Bug #2136800 - openconnect fails due to missing symbol xmlIOFTPRead

https://bugzilla.redhat.com/show_bug.cgi?id=2136800

su -c 'dnf upgrade --advisory FEDORA-2022-aeafd24818' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 36
Version: 1.2.33
Release: 3.fc36
Summary: Library providing support for "XML Signature" and "XML Encryption" standards

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here