Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 454
Alerts This Week
Warning Icon 1 454

Mageia 7 & 8: 2021-0232 Moderate: Libxml2 Exponential Entity Expansion

mageia
Calendar Grey June 8, 2021
Scroller Mageia
Recent updates to libxml2 address a significant security vulnerability related to exponential entity expansion attacks. This is essential for users of Mageia.
Exponential entity expansion attack bypasses all existing protection mechanisms

Summary

Exponential entity expansion attack bypasses all existing protection mechanisms. (CVE-2021-3541).

References

- https://bugs.mageia.org/show_bug.cgi?id=29039

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/NYSYJVWYEQHFG2TBIQJRJ5COUR5LNFJJ/

- https://lists.debian.org/debian-lts-announce/2021/05/msg00024.html

- https://www.cve.org/CVERecord?id=CVE-2021-3541

Resolution

SRPMS

- 8/core/libxml2-2.9.10-7.2.mga8

- 7/core/libxml2-2.9.9-2.7.mga7

Publication date: 08 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0232.html
Type: security
CVE: CVE-2021-3541

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.