Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Mageia 7 & 8: 2021-0232 Moderate: Libxml2 Exponential Entity Expansion

mageia
Calendar Grey June 8, 2021
Dist Mageia Esm H88
Recent updates to libxml2 address a significant security vulnerability related to exponential entity expansion attacks. This is essential for users of Mageia.
Exponential entity expansion attack bypasses all existing protection mechanisms

Summary

Exponential entity expansion attack bypasses all existing protection mechanisms. (CVE-2021-3541).

References

- https://bugs.mageia.org/show_bug.cgi?id=29039

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/NYSYJVWYEQHFG2TBIQJRJ5COUR5LNFJJ/

- https://lists.debian.org/debian-lts-announce/2021/05/msg00024.html

- https://www.cve.org/CVERecord?id=CVE-2021-3541

Resolution

SRPMS

- 8/core/libxml2-2.9.10-7.2.mga8

- 7/core/libxml2-2.9.9-2.7.mga7

Publication date: 08 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0232.html
Type: security
CVE: CVE-2021-3541

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here