Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 7: MGASA-2020-0101 Moderate: libxml2 Memory Leak and Loop Issues

mageia
Calendar Grey February 24, 2020
Dist Mageia Esm H88
Recent libxml2 updates have addressed concerns regarding memory leaks and infinite loop problems. Important security patches have been released for Mageia users.

Updated libxml2 packages fix security vulnerabilities: xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak (CVE-2019-20388).

Summary

Updated libxml2 packages fix security vulnerabilities:
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak (CVE-2019-20388).
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation (CVE-2020-7595).

References

- https://bugs.mageia.org/show_bug.cgi?id=26222

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/

- https://www.cve.org/CVERecord?id=CVE-2019-20388

- https://www.cve.org/CVERecord?id=CVE-2020-7595

Resolution

SRPMS

- 7/core/libxml2-2.9.9-2.3.mga7

Publication date: 24 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0101.html
Type: security
CVE: CVE-2019-20388, CVE-2020-7595

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here