CLSA-2021-1640700710
Dashboard / Vulnerabilities / CLSA-2021-1640700710
CLSA-2021-1640700710
Summary: Fix CVE(s): CVE-2021-3517, CVE-2021-3516, CVE-2020-24977, CVE-2021-3541, CVE-2021-3537, CVE-2021-3518, CVE-2019-20388, CVE-2017-8872
Details: * SECURITY UPDATE: Out-of-bounds array access - debian/patches/CVE-2021-3517.patch: Validate UTF8 in xmlEncodeEntities - CVE-2021-3517 * SECURITY UPDATE: Use-after-free error - debian/patches/CVE-2021-3518.patch: Fix use-after-free with 'xmllint --xinclude --dropdtd' - CVE-2021-3518 * SECURITY UPDATE: Null pointer dereference while parsing in recovery mode - debian/patches/CVE-2021-3537.patch: Propagate error in xmlParseElementChildrenContentDeclPriv - CVE-2021-3537 * SECURITY UPDATE: Parser fix for the billion laugs attach - debian/patches/CVE-2021-3541.patch: Fix parameter entities expansion in xmlParserEntityCheck - CVE-2021-3541 * SECURITY UPDATE: Miscalculation of available bytes when parsing - debian/patches/CVE-2017-8872.patch: Free input buffer in xmlHaltParser - CVE-2017-8872 * SECURITY UPDATE: Memory leak - debian/patches/CVE-2019-20388.patch: Fix memory leak in xmlSchemaValidateStream - CVE-2019-20388 * SECURITY UPDATE: Out-of-bounds array access - debian/patches/CVE-2020-24977.patch: Fix out-of-bounds read with 'xmllint --htmlout' - CVE-2020-24977 * SECURITY UPDATE: Use-after-free error - debian/patches/CVE-2021-3516.patch: Fix use-after-free with 'xmllint --html --push' - CVE-2021-3516
Affected packages
Package
Name: libxml2
Purl: pkg:deb/tuxcare/libxml2?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
