Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 37: FEDORA-2022-a6812b0224 Moderate: xmlsec1 Integer Overflow Fix

fedora
Calendar Grey November 12, 2022
Dist Fedora Esm H88
Upgrade your Fedora installation by applying xmlsec1 patches that address severe integer overflow vulnerabilities, ensuring enhanced safety.
Update to 2.10.3 * Fix CVE-2022-40303 * Fix CVE-2022-40304

Summary

XML Security Library is a C library based on LibXML2 and OpenSSL.

The library was created with a goal to support major XML security

standards "XML Digital Signature" and "XML Encryption".

Update to 2.10.3 * Fix CVE-2022-40303 * Fix CVE-2022-40304

* Mon Oct 24 2022 David King - 1.2.34-4

- Rebuild against libxml2 (#2136800)

* Mon Oct 24 2022 David King - 1.2.34-3

- Rebuild against libxml2 (#2136800)

[ 1 ] Bug #2119077 - libxml2-2.10.2 is available

https://bugzilla.redhat.com/show_bug.cgi?id=2119077

[ 2 ] Bug #2136274 - CVE-2022-40303 libxml2: integer overflows with XML_PARSE_HUGE [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2136274

[ 3 ] Bug #2136293 - CVE-2022-40304 libxml2: dict corruption caused by entity reference cycles [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2136293

[ 4 ] Bug #2136800 - openconnect fails due to missing symbol xmlIOFTPRead

https://bugzilla.redhat.com/show_bug.cgi?id=2136800

su -c 'dnf upgrade --advisory FEDORA-2022-a6812b0224' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 37
Version: 1.2.34
Release: 4.fc37
Summary: Library providing support for "XML Signature" and "XML Encryption" standards

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here