Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:2835-1 Critical Security Updates for libxml2 Released

suse
Calendar Grey November 6, 2022
Dist Suse Esm H88
SUSE Container Advisory responds to vulnerabilities in libxml2, incorporating several critical patches within this significant enhancement.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2022:3871-1 Released: Fri Nov 4 13:26:29 2022 Summary: Security update for libxml2 Type: security Severity: important

References

References : 1201978 1204366 1204367 CVE-2016-3709 CVE-2022-40303 CVE-2022-40304

1201978,1204366,1204367,CVE-2016-3709,CVE-2022-40303,CVE-2022-40304

This update for libxml2 fixes the following issues:

- CVE-2016-3709: Fixed possible XSS vulnerability (bsc#1201978).

- CVE-2022-40303: Fixed integer overflows with XML_PARSE_HUGE (bsc#1204366).

- CVE-2022-40304: Fixed dict corruption caused by entity reference cycles (bsc#1204367).

The following package changes have been done:

- libxml2-2-2.9.7-150000.3.51.1 updated

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:2835-1
Container Tags : suse/sle15:15.2 , suse/sle15:15.2.9.5.218
Container Release : 9.5.218
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here