Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: MGASA-2022-0412 Moderate: Libxml2 Integer Overflow Threat

mageia
Calendar Grey November 8, 2022
Dist Mageia Esm H88
Enhanced libxml2 versions in Mageia address critical integer overflow and dictionary corruption security flaws. Discover comprehensive information here.
Integer overflows with XML_PARSE_HUGE

Summary

Integer overflows with XML_PARSE_HUGE. (CVE-2022-40303) Dict corruption caused by entity reference cycles. (CVE-2022-40304)

References

- https://bugs.mageia.org/show_bug.cgi?id=31020

-

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MNZAUJGHSPCIYDNVSWTSDYNJMQW7Z2JZ/

- https://lists.suse.com/pipermail/sle-security-updates/2022-October/012663.html

- https://lists.debian.org/debian-lts-announce/2022/10/msg00040.html

- https://www.cve.org/CVERecord?id=CVE-2022-40303

- https://www.cve.org/CVERecord?id=CVE-2022-40304

Resolution

SRPMS

- 8/core/libxml2-2.9.10-7.6.mga8

Publication date: 08 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0412.html
Type: security
CVE: CVE-2022-40303, CVE-2022-40304

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here