An update for libxml2 is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS,openEuler-22.03-LTS-SP1,openEuler-22.03-LTS-SP2 and openEuler-22.03-LTS-SP3
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2024-1183
Final
1.0
1.0
2024-02-23
Initial
2024-02-23
2024-02-23
openEuler SA Tool V1.0
2024-02-23
libxml2 security update
An update for libxml2 is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS,openEuler-22.03-LTS-SP1,openEuler-22.03-LTS-SP2 and openEuler-22.03-LTS-SP3.
Library providing XML and HTML support.
Security Fix(es):
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.(CVE-2024-25062)
An update for libxml2 is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS,openEuler-22.03-LTS-SP1,openEuler-22.03-LTS-SP2 and openEuler-22.03-LTS-SP3.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
High
libxml2
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1183
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2024-25062
https://nvd.nist.gov/vuln/detail/CVE-2024-25062
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS
openEuler-22.03-LTS-SP1
openEuler-22.03-LTS-SP2
openEuler-22.03-LTS-SP3
python2-libxml2-2.9.10-37.oe1.aarch64.rpm
libxml2-2.9.10-37.oe1.aarch64.rpm
libxml2-devel-2.9.10-37.oe1.aarch64.rpm
libxml2-debuginfo-2.9.10-37.oe1.aarch64.rpm
python3-libxml2-2.9.10-37.oe1.aarch64.rpm
libxml2-debugsource-2.9.10-37.oe1.aarch64.rpm
python2-libxml2-2.9.10-39.oe2003sp4.aarch64.rpm
python3-libxml2-2.9.10-39.oe2003sp4.aarch64.rpm
libxml2-2.9.10-39.oe2003sp4.aarch64.rpm
libxml2-devel-2.9.10-39.oe2003sp4.aarch64.rpm
libxml2-debugsource-2.9.10-39.oe2003sp4.aarch64.rpm
libxml2-debuginfo-2.9.10-39.oe2003sp4.aarch64.rpm
libxml2-debugsource-2.9.12-19.oe2203.aarch64.rpm
libxml2-2.9.12-19.oe2203.aarch64.rpm
libxml2-debuginfo-2.9.12-19.oe2203.aarch64.rpm
python3-libxml2-2.9.12-19.oe2203.aarch64.rpm
libxml2-devel-2.9.12-19.oe2203.aarch64.rpm
libxml2-debugsource-2.9.14-10.oe2203sp1.aarch64.rpm
libxml2-2.9.14-10.oe2203sp1.aarch64.rpm
python3-libxml2-2.9.14-10.oe2203sp1.aarch64.rpm
libxml2-debuginfo-2.9.14-10.oe2203sp1.aarch64.rpm
libxml2-devel-2.9.14-10.oe2203sp1.aarch64.rpm
libxml2-debuginfo-2.9.14-10.oe2203sp2.aarch64.rpm
libxml2-debugsource-2.9.14-10.oe2203sp2.aarch64.rpm
libxml2-2.9.14-10.oe2203sp2.aarch64.rpm
python3-libxml2-2.9.14-10.oe2203sp2.aarch64.rpm
libxml2-devel-2.9.14-10.oe2203sp2.aarch64.rpm
python3-libxml2-2.9.14-10.oe2203sp3.aarch64.rpm
libxml2-debugsource-2.9.14-10.oe2203sp3.aarch64.rpm
libxml2-2.9.14-10.oe2203sp3.aarch64.rpm
libxml2-devel-2.9.14-10.oe2203sp3.aarch64.rpm
libxml2-debuginfo-2.9.14-10.oe2203sp3.aarch64.rpm
libxml2-help-2.9.10-37.oe1.noarch.rpm
libxml2-help-2.9.10-39.oe2003sp4.noarch.rpm
libxml2-help-2.9.12-19.oe2203.noarch.rpm
libxml2-help-2.9.14-10.oe2203sp1.noarch.rpm
libxml2-help-2.9.14-10.oe2203sp2.noarch.rpm
libxml2-help-2.9.14-10.oe2203sp3.noarch.rpm
libxml2-2.9.10-37.oe1.src.rpm
libxml2-2.9.10-39.oe2003sp4.src.rpm
libxml2-2.9.12-19.oe2203.src.rpm
libxml2-2.9.14-10.oe2203sp1.src.rpm
libxml2-2.9.14-10.oe2203sp2.src.rpm
libxml2-2.9.14-10.oe2203sp3.src.rpm
libxml2-devel-2.9.10-37.oe1.x86_64.rpm
libxml2-debuginfo-2.9.10-37.oe1.x86_64.rpm
python2-libxml2-2.9.10-37.oe1.x86_64.rpm
python3-libxml2-2.9.10-37.oe1.x86_64.rpm
libxml2-2.9.10-37.oe1.x86_64.rpm
libxml2-debugsource-2.9.10-37.oe1.x86_64.rpm
libxml2-devel-2.9.10-39.oe2003sp4.x86_64.rpm
python2-libxml2-2.9.10-39.oe2003sp4.x86_64.rpm
python3-libxml2-2.9.10-39.oe2003sp4.x86_64.rpm
libxml2-debugsource-2.9.10-39.oe2003sp4.x86_64.rpm
libxml2-debuginfo-2.9.10-39.oe2003sp4.x86_64.rpm
libxml2-2.9.10-39.oe2003sp4.x86_64.rpm
libxml2-debuginfo-2.9.12-19.oe2203.x86_64.rpm
libxml2-debugsource-2.9.12-19.oe2203.x86_64.rpm
python3-libxml2-2.9.12-19.oe2203.x86_64.rpm
libxml2-devel-2.9.12-19.oe2203.x86_64.rpm
libxml2-2.9.12-19.oe2203.x86_64.rpm
python3-libxml2-2.9.14-10.oe2203sp1.x86_64.rpm
libxml2-2.9.14-10.oe2203sp1.x86_64.rpm
libxml2-devel-2.9.14-10.oe2203sp1.x86_64.rpm
libxml2-debugsource-2.9.14-10.oe2203sp1.x86_64.rpm
libxml2-debuginfo-2.9.14-10.oe2203sp1.x86_64.rpm
python3-libxml2-2.9.14-10.oe2203sp2.x86_64.rpm
libxml2-debuginfo-2.9.14-10.oe2203sp2.x86_64.rpm
libxml2-debugsource-2.9.14-10.oe2203sp2.x86_64.rpm
libxml2-2.9.14-10.oe2203sp2.x86_64.rpm
libxml2-devel-2.9.14-10.oe2203sp2.x86_64.rpm
libxml2-debuginfo-2.9.14-10.oe2203sp3.x86_64.rpm
libxml2-2.9.14-10.oe2203sp3.x86_64.rpm
python3-libxml2-2.9.14-10.oe2203sp3.x86_64.rpm
libxml2-debugsource-2.9.14-10.oe2203sp3.x86_64.rpm
libxml2-devel-2.9.14-10.oe2203sp3.x86_64.rpm
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
2024-02-23
CVE-2024-25062
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS
openEuler-22.03-LTS-SP1
openEuler-22.03-LTS-SP2
openEuler-22.03-LTS-SP3
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
libxml2 security update
2024-02-23
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1183