Integer overflows with XML_PARSE_HUGE. (CVE-2022-40303)
Dict corruption caused by entity reference cycles. (CVE-2022-40304)
- https://bugs.mageia.org/show_bug.cgi?id=31020
-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MNZAUJGHSPCIYDNVSWTSDYNJMQW7Z2JZ/
- https://lists.suse.com/pipermail/sle-security-updates/2022-October/012663.html
- https://lists.debian.org/debian-lts-announce/2022/10/msg00040.html
- https://www.cve.org/CVERecord?id=CVE-2022-40303
- https://www.cve.org/CVERecord?id=CVE-2022-40304
- 8/core/libxml2-2.9.10-7.6.mga8
Get the latest Linux and open source security news straight to your inbox.