Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

Mageia 7: MGASA-2020-0101 Moderate: libxml2 Memory Leak and Loop Issues

mageia
Calendar Grey February 24, 2020
Scroller Mageia
Recent libxml2 updates have addressed concerns regarding memory leaks and infinite loop problems. Important security patches have been released for Mageia users.

Updated libxml2 packages fix security vulnerabilities: xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak (CVE-2019-20388).

Summary

Updated libxml2 packages fix security vulnerabilities:
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak (CVE-2019-20388).
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation (CVE-2020-7595).

References

- https://bugs.mageia.org/show_bug.cgi?id=26222

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/

- https://www.cve.org/CVERecord?id=CVE-2019-20388

- https://www.cve.org/CVERecord?id=CVE-2020-7595

Resolution

SRPMS

- 7/core/libxml2-2.9.9-2.3.mga7

Publication date: 24 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0101.html
Type: security
CVE: CVE-2019-20388, CVE-2020-7595

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.