MGASA-2021-0474 - Updated xstream/xmlpull/mxparser packages fix security vulnerability

Publication date: 13 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0474.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-39139,
     CVE-2021-39140,
     CVE-2021-39141,
     CVE-2021-39144,
     CVE-2021-39145,
     CVE-2021-39146,
     CVE-2021-39147,
     CVE-2021-39148,
     CVE-2021-39149,
     CVE-2021-39150,
     CVE-2021-39151,
     CVE-2021-39152,
     CVE-2021-39153,
     CVE-2021-39154

Multiple security vulnerabilities have been discovered in XStream. See
references for details.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29512
- https://www.debian.org/lts/security/2021/dla-2769
- https://lists.fedoraproject.org/archives/list/[email protected]/thread/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39139
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39140
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39141
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39144
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39145
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39146
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39147
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39148
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39149
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39150
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39151
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39152
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39153
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39154

SRPMS:
- 8/core/xstream-1.4.18-1.mga8
- 8/core/xmlpull-1.2.0-1.mga8
- 8/core/mxparser-1.2.2-1.mga8