Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves six vulnerabilities and has eight fixes can now be installed.. # Security update for libxslt, libxml2 Announcement ID: SUSE-SU-2026:20657-1 Release Date: 2026-03-06T11:35:58Z Rating: moderate References: * bsc#1247850 * bsc#1247858 * bsc#1250553 * bsc#1256804 * bsc#1256805 * bsc#1256807 * bsc#1256808 * bsc#1256809 * bsc#1256810 * bsc#1256811 * bsc#1256812 * bsc#1257593 * bsc#1257594 * bsc#1257595 Cross-References: * CVE-2025-10911 * CVE-2025-8732 * CVE-2026-0989 * CVE-2026-0990 * CVE-2026-0992 * CVE-2026-1757 CVSS scores: * CVE-2025-10911 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-10911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-10911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8732 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8732 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-8732 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8732 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0989 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0989 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0989 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0990 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0990 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0990 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0992 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0992 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0992( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-1757 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-1757 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-1757 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has eight fixes can now be installed. ## Description: This update for libxslt, libxml2 fixes the following issues: libxml2: * CVE-2026-0990: call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI` (bsc#1256807, bsc#1256811) * CVE-2026-0992: excessive resource consumption when processing XML catalogs due to exponential behavior when handling ` ` elements (bsc#1256808, bsc#1256809, bsc#1256812) * CVE-2025-8732: infinite recursion in catalog parsing functions when processing malformed SGML catalog files (bsc#1247858, bsc#1247850) * CVE-2026-1757: memory leak in the `xmllint` interactive shell (bsc#1257593, bsc#1257594, bsc#1257595) * CVE-2025-10911: use-after-free with key data stored cross-RVT (bsc#1250553) * CVE-2026-0989: call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth when resolving ` ` directives (bsc#1256804, bsc#1256805, bsc#1256810) libxslt: * CVE-2025-10911 will be fixed on libxml2 side instead [bsc#1250553] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-429=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libxml2-tools-2.11.6-slfo.1.1_8.1 * libexslt0-1.1.38-slfo.1.1_6.1 * libxml2-2-2.11.6-slfo.1.1_8.1 * libxml2-debugsource-2.11.6-slfo.1.1_8.1 *libxslt1-debuginfo-1.1.38-slfo.1.1_6.1 * libxml2-2-debuginfo-2.11.6-slfo.1.1_8.1 * libxml2-tools-debuginfo-2.11.6-slfo.1.1_8.1 * python311-libxml2-debuginfo-2.11.6-slfo.1.1_8.1 * python311-libxml2-2.11.6-slfo.1.1_8.1 * libexslt0-debuginfo-1.1.38-slfo.1.1_6.1 * libxslt1-1.1.38-slfo.1.1_6.1 * libxml2-python-debugsource-2.11.6-slfo.1.1_8.1 * libxslt-debugsource-1.1.38-slfo.1.1_6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10911.html * https://www.suse.com/security/cve/CVE-2025-8732.html * https://www.suse.com/security/cve/CVE-2026-0989.html * https://www.suse.com/security/cve/CVE-2026-0990.html * https://www.suse.com/security/cve/CVE-2026-0992.html * https://www.suse.com/security/cve/CVE-2026-1757.html * https://bugzilla.suse.com/show_bug.cgi?id=1247850 * https://bugzilla.suse.com/show_bug.cgi?id=1247858 * https://bugzilla.suse.com/show_bug.cgi?id=1250553 * https://bugzilla.suse.com/show_bug.cgi?id=1256804 * https://bugzilla.suse.com/show_bug.cgi?id=1256805 * https://bugzilla.suse.com/show_bug.cgi?id=1256807 * https://bugzilla.suse.com/show_bug.cgi?id=1256808 * https://bugzilla.suse.com/show_bug.cgi?id=1256809 * https://bugzilla.suse.com/show_bug.cgi?id=1256810 * https://bugzilla.suse.com/show_bug.cgi?id=1256811 * https://bugzilla.suse.com/show_bug.cgi?id=1256812 * https://bugzilla.suse.com/show_bug.cgi?id=1257593 * https://bugzilla.suse.com/show_bug.cgi?id=1257594 * https://bugzilla.suse.com/show_bug.cgi?id=1257595 . Update addresses six security weaknesses in libxslt and libxml2 for SUSE Linux Micro 6.1. Immediate installation recommended.. libxml2 update, libxslt security, SUSE vulnerabilities, Linux micro security. . LinuxSecurity.com Team
An update that solves six vulnerabilities and has eight fixes can now be installed.. # Security update for libxslt, libxml2 Announcement ID: SUSE-SU-2026:20707-1 Release Date: 2026-03-06T11:58:49Z Rating: moderate References: * bsc#1247850 * bsc#1247858 * bsc#1250553 * bsc#1256804 * bsc#1256805 * bsc#1256807 * bsc#1256808 * bsc#1256809 * bsc#1256810 * bsc#1256811 * bsc#1256812 * bsc#1257593 * bsc#1257594 * bsc#1257595 Cross-References: * CVE-2025-10911 * CVE-2025-8732 * CVE-2026-0989 * CVE-2026-0990 * CVE-2026-0992 * CVE-2026-1757 CVSS scores: * CVE-2025-10911 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-10911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-10911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8732 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8732 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-8732 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8732 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0989 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0989 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0989 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0990 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0990 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0990 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0992 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0992 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0992( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-1757 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-1757 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-1757 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has eight fixes can now be installed. ## Description: This update for libxslt, libxml2 fixes the following issues: Changes in libxml2: * CVE-2026-0990: call stack overflow may lead to application crash due to infinite recursion in `xmlCatalogXMLResolveURI` (bsc#1256807, bsc#1256811). * CVE-2026-0992: excessive resource consumption when processing XML catalogs due to exponential behavior when handling `nextCatalog` elements (bsc#1256809, bsc#1256812). * CVE-2025-8732: infinite recursion in catalog parsing functions when processing malformed SGML catalog files (bsc#1247858). * CVE-2026-1757: memory leak in the `xmllint` interactive shell (bsc#1257594, bsc#1257595). * CVE-2025-10911: parsing xsl nodes may lead to use-after-free with key data stored cross-RVT (bsc#1250553). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-608=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libxml2-debugsource-2.11.6-12.1 * libexslt0-debuginfo-1.1.38-8.1 * python311-libxml2-debuginfo-2.11.6-12.1 * libxslt1-1.1.38-8.1 * libxml2-python-debugsource-2.11.6-12.1 * libexslt0-1.1.38-8.1 * libxml2-2-2.11.6-12.1 * libxslt-debugsource-1.1.38-8.1 * libxml2-tools-debuginfo-2.11.6-12.1 * libxslt1-debuginfo-1.1.38-8.1 * libxml2-2-debuginfo-2.11.6-12.1 * python311-libxml2-2.11.6-12.1 *libxml2-tools-2.11.6-12.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10911.html * https://www.suse.com/security/cve/CVE-2025-8732.html * https://www.suse.com/security/cve/CVE-2026-0989.html * https://www.suse.com/security/cve/CVE-2026-0990.html * https://www.suse.com/security/cve/CVE-2026-0992.html * https://www.suse.com/security/cve/CVE-2026-1757.html * https://bugzilla.suse.com/show_bug.cgi?id=1247850 * https://bugzilla.suse.com/show_bug.cgi?id=1247858 * https://bugzilla.suse.com/show_bug.cgi?id=1250553 * https://bugzilla.suse.com/show_bug.cgi?id=1256804 * https://bugzilla.suse.com/show_bug.cgi?id=1256805 * https://bugzilla.suse.com/show_bug.cgi?id=1256807 * https://bugzilla.suse.com/show_bug.cgi?id=1256808 * https://bugzilla.suse.com/show_bug.cgi?id=1256809 * https://bugzilla.suse.com/show_bug.cgi?id=1256810 * https://bugzilla.suse.com/show_bug.cgi?id=1256811 * https://bugzilla.suse.com/show_bug.cgi?id=1256812 * https://bugzilla.suse.com/show_bug.cgi?id=1257593 * https://bugzilla.suse.com/show_bug.cgi?id=1257594 * https://bugzilla.suse.com/show_bug.cgi?id=1257595 . Update for SUSE addresses several important issues in libxslt and libxml2, enhancing system security against potential threats.. libxslt security, libxml2 update, SUSE vulnerabilities, system security fixes, Linux application security. . LinuxSecurity.com Team
It was discovered that libxml2, the GNOME XML library, was vulnerable to integer overflows and memory corruption. CVE-2022-40303 . -------------------------------------------------------------------------Debian LTS Advisory DLA-3172-1
The updated packages fix security vulnerabilities: Use-after-free in xmlEncodeEntitiesInternal() in entities.c. (CVE-2021-3516) . MGASA-2021-0213 - Updated libxml2 packages fix security vulnerabilities Publication date: 19 May 2021 URL: https://advisories.mageia.org/MGASA-2021-0213.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3516, CVE-2021-3517, CVE-2021-3518, CVE-2021-3537 The updated packages fix security vulnerabilities: Use-after-free in xmlEncodeEntitiesInternal() in entities.c. (CVE-2021-3516) Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c. (CVE-2021-3517) Use-after-free in xmlXIncludeDoProcess() in xinclude.c. (CVE-2021-3518) NULL pointer dereference in valid.c in xmlValidBuildAContentModel. (CVE-2021-3537) References: - https://bugs.mageia.org/show_bug.cgi?id=28902 - https://lists.debian.org/debian-lts-announce/2021/05/msg00008.html - - https://lists.fedoraproject.org/archives/list/
Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-ff317550e4 2020-11-20 01:38:40.112323 --------------------------------------------------------------------------------Name : mingw-libxml2 Product : Fedora 33 Version : 2.9.10 Release : 8.fc33 URL : Summary : MinGW Windows libxml2 XML processing library Description : MinGW Windows libxml2 XML processing library. --------------------------------------------------------------------------------Update Information: Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot. --------------------------------------------------------------------------------ChangeLog: * Wed Nov 11 2020 Richard W.M. Jones - 2.9.10-8 - Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot. --------------------------------------------------------------------------------References: [ 1 ] Bug #1877788 - CVE-2020-24977 libxml2: Buffer Overflow vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c https://bugzilla.redhat.com/show_bug.cgi?id=1877788 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-ff317550e4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-b60dbdd538 2020-09-19 22:37:58.507772 --------------------------------------------------------------------------------Name : mingw-libxml2 Product : Fedora 32 Version : 2.9.10 Release : 3.fc32 URL : Summary : MinGW Windows libxml2 XML processing library Description : MinGW Windows libxml2 XML processing library. --------------------------------------------------------------------------------Update Information: Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789). --------------------------------------------------------------------------------ChangeLog: * Fri Sep 11 2020 Richard W.M. Jones - 2.9.10-7 - Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789). * Tue Jul 28 2020 Fedora Release Engineering - 2.9.10-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1877788 - CVE-2020-24977 libxml2: Buffer Overflow vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c https://bugzilla.redhat.com/show_bug.cgi?id=1877788 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-b60dbdd538' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for libxml2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libxml2 security update Advisory ID: RHSA-2020:1190-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1190 Issue date: 2020-03-31 CVE Names: CVE-2015-8035 CVE-2016-5131 CVE-2017-15412 CVE-2017-18258 CVE-2018-14404 CVE-2018-14567 ==================================================================== 1. Summary: An update for libxml2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: Use after free triggered by XPointer paths beginning with range-to (CVE-2016-5131) * libxml2: Use after free inxmlXPathCompOpEvalPositionalPredicate() function in xpath.c (CVE-2017-15412) * libxml2: DoS caused by incorrect error detection during XZ decompression (CVE-2015-8035) * libxml2: NULL pointer dereference in xmlXPathCompOpEval() function in xpath.c (CVE-2018-14404) * libxml2: Unrestricted memory usage in xz_head() function in xzlib.c (CVE-2017-18258) * libxml2: Infinite loop caused by incorrect error detection during LZMA decompression (CVE-2018-14567) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The desktop must be restarted (log out, then log back in) for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1277146 - CVE-2015-8035 libxml2: DoS caused by incorrect error detection during XZ decompression 1358641 - CVE-2016-5131 libxml2: Use after free triggered by XPointer paths beginning with range-to 1523128 - CVE-2017-15412 libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c 1566749 - CVE-2017-18258 libxml2: Unrestricted memory usage in xz_head() function in xzlib.c 1595985 - CVE-2018-14404 libxml2: NULL pointer dereference in xmlXPathCompOpEval() function in xpath.c 1619875 - CVE-2018-14567 libxml2: Infinite loop caused by incorrect error detection during LZMA decompression 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: libxml2-2.9.1-6.el7.4.src.rpm x86_64: libxml2-2.9.1-6.el7.4.i686.rpm libxml2-2.9.1-6.el7.4.x86_64.rpm libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-python-2.9.1-6.el7.4.x86_64.rpm Red Hat EnterpriseLinux Client Optional (v. 7): x86_64: libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-devel-2.9.1-6.el7.4.i686.rpm libxml2-devel-2.9.1-6.el7.4.x86_64.rpm libxml2-static-2.9.1-6.el7.4.i686.rpm libxml2-static-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: libxml2-2.9.1-6.el7.4.src.rpm x86_64: libxml2-2.9.1-6.el7.4.i686.rpm libxml2-2.9.1-6.el7.4.x86_64.rpm libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-python-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-devel-2.9.1-6.el7.4.i686.rpm libxml2-devel-2.9.1-6.el7.4.x86_64.rpm libxml2-static-2.9.1-6.el7.4.i686.rpm libxml2-static-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: libxml2-2.9.1-6.el7.4.src.rpm ppc64: libxml2-2.9.1-6.el7.4.ppc.rpm libxml2-2.9.1-6.el7.4.ppc64.rpm libxml2-debuginfo-2.9.1-6.el7.4.ppc.rpm libxml2-debuginfo-2.9.1-6.el7.4.ppc64.rpm libxml2-devel-2.9.1-6.el7.4.ppc.rpm libxml2-devel-2.9.1-6.el7.4.ppc64.rpm libxml2-python-2.9.1-6.el7.4.ppc64.rpm ppc64le: libxml2-2.9.1-6.el7.4.ppc64le.rpm libxml2-debuginfo-2.9.1-6.el7.4.ppc64le.rpm libxml2-devel-2.9.1-6.el7.4.ppc64le.rpm libxml2-python-2.9.1-6.el7.4.ppc64le.rpm s390x: libxml2-2.9.1-6.el7.4.s390.rpm libxml2-2.9.1-6.el7.4.s390x.rpm libxml2-debuginfo-2.9.1-6.el7.4.s390.rpm libxml2-debuginfo-2.9.1-6.el7.4.s390x.rpm libxml2-devel-2.9.1-6.el7.4.s390.rpm libxml2-devel-2.9.1-6.el7.4.s390x.rpm libxml2-python-2.9.1-6.el7.4.s390x.rpm x86_64: libxml2-2.9.1-6.el7.4.i686.rpm libxml2-2.9.1-6.el7.4.x86_64.rpm libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-devel-2.9.1-6.el7.4.i686.rpm libxml2-devel-2.9.1-6.el7.4.x86_64.rpm libxml2-python-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: libxml2-debuginfo-2.9.1-6.el7.4.ppc.rpm libxml2-debuginfo-2.9.1-6.el7.4.ppc64.rpm libxml2-static-2.9.1-6.el7.4.ppc.rpm libxml2-static-2.9.1-6.el7.4.ppc64.rpm ppc64le: libxml2-debuginfo-2.9.1-6.el7.4.ppc64le.rpm libxml2-static-2.9.1-6.el7.4.ppc64le.rpm s390x: libxml2-debuginfo-2.9.1-6.el7.4.s390.rpm libxml2-debuginfo-2.9.1-6.el7.4.s390x.rpm libxml2-static-2.9.1-6.el7.4.s390.rpm libxml2-static-2.9.1-6.el7.4.s390x.rpm x86_64: libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-static-2.9.1-6.el7.4.i686.rpm libxml2-static-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: libxml2-2.9.1-6.el7.4.src.rpm x86_64: libxml2-2.9.1-6.el7.4.i686.rpm libxml2-2.9.1-6.el7.4.x86_64.rpm libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-devel-2.9.1-6.el7.4.i686.rpm libxml2-devel-2.9.1-6.el7.4.x86_64.rpm libxml2-python-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-static-2.9.1-6.el7.4.i686.rpm libxml2-static-2.9.1-6.el7.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2015-8035 https://access.redhat.com/security/cve/CVE-2016-5131 https://access.redhat.com/security/cve/CVE-2017-15412 https://access.redhat.com/security/cve/CVE-2017-18258 https://access.redhat.com/security/cve/CVE-2018-14404 https://access.redhat.com/security/cve/CVE-2018-14567 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/7/html/7.8_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iQIVAwUBXoOdR9zjgjWX9erEAQhgbQ/+JolcknqNffv7HQZNxYOtS/M2Zx/E3IB4 QwmkXhfmgV44ig4prUpghE/+O5eTUPjqSq6rHjih/pjCjG4bVcK6BptxBFi7WQwo GM0ryvm0p0fib0dy+Ov3NNC6Dhg32NIVwC0pWTIEdYcOGBfDY3mXlLXx5aHefisu p1C7F6rP4xxMRDOlQhAB4UPMkPSD/MtKIyxIEqiAT5olybSTl0um2AB5XtLlCbkT h4IXDsAyswvBIS/bxnyZkn6oHEiD3JBwcP+ZU0jgSEy34O92ttV7hRQb1H1+YHOO li1bX5IcbmFzATwBfCZQmNfrp/XU4Ra28GT/3JGntnhhxFmz1xe/h5YNJTwZ+0TX yxKZdAz3brm/mt6uvbY4PpGERyA+X/Moz4ToXCEL2jVfSXbOuajRtCV8Cp3X7bCd Ed2imuXZQPpUXNVdF73RJ7YB6vEhQRIdlKgEXzPPpuHFH1HprvSLoJyrDD1T8bfx TVrrmvtWKtXq0DYSD7wGw23WZJJeUIgyKiZNTlIxvb0c7r8+aZ+toY07sZlBkTCA cjWNRnHDNkdYH2ZoNPQlzYzk5rSYGqhoOvF85pNCY4v4fofyMEnyAY7MEZ/Z991X Ko2ShKSzEtKSMcx2B2wPg+hFcACP8HbKxSbW3SzoCSKCOGEAPLQlJ5eHXwLOAO3Q IZIK7xZywNw=8RZh -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Security fix for CVE-2017-5662. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-aff3dd3101 2017-05-09 21:16:27.649955 --------------------------------------------------------------------------------Name : batik Product : Fedora 24 Version : 1.8 Release : 9.fc24 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-5662 --------------------------------------------------------------------------------References: [ 1 ] Bug #1443592 - CVE-2017-5662 batik: XML external entity processing vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1443592 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade batik' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.