Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 7: MGASA-2021-0002 Critical: Libxml2 Buffer Overflow

mageia
Calendar Grey January 4, 2021
Dist Mageia Esm H88
MGASA-2021-0011 updates openssl packages to mitigate a major Security Flaw that was disclosed on Jan 10, 2021.
libxml2 v2.9.10 and earlier has a global Buffer Overflow vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c (CVE-2020-24977)

Summary

libxml2 v2.9.10 and earlier has a global Buffer Overflow vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c (CVE-2020-24977).

References

- https://bugs.mageia.org/show_bug.cgi?id=27300

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2NQ5GTDYOVH26PBCPYXXMGW5ZZXWMGZC/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ENEHQIBMSI6TZVS35Y6I4FCTYUQDLJVP/

- https://www.cve.org/CVERecord?id=CVE-2020-24977

Resolution

SRPMS

- 7/core/libxml2-2.9.9-2.5.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 04 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0002.html
Type: security
CVE: CVE-2020-24977

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here