MGASA-2020-0101 - Updated libxml2_2 packages fix security vulnerabilities

Publication date: 24 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0101.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-20388,
     CVE-2020-7595

Updated libxml2 packages fix security vulnerabilities:

xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an
xmlSchemaValidateStream memory leak (CVE-2019-20388).

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite
loop in a certain end-of-file situation (CVE-2020-7595).

References:
- https://bugs.mageia.org/show_bug.cgi?id=26222
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20388
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7595

SRPMS:
- 7/core/libxml2-2.9.9-2.3.mga7

Mageia 2020-0101: libxml2_2 security update

Updated libxml2 packages fix security vulnerabilities: xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak (CVE-2019-20388).

Summary

Updated libxml2 packages fix security vulnerabilities:
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak (CVE-2019-20388).
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation (CVE-2020-7595).

References

- https://bugs.mageia.org/show_bug.cgi?id=26222

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20388

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7595

Resolution

MGASA-2020-0101 - Updated libxml2_2 packages fix security vulnerabilities

SRPMS

- 7/core/libxml2-2.9.9-2.3.mga7

Severity
Publication date: 24 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0101.html
Type: security
CVE: CVE-2019-20388, CVE-2020-7595

Related News