CLSA-2022-1670518262
Dashboard / Vulnerabilities / CLSA-2022-1670518262
CLSA-2022-1670518262
Summary: Fix CVE(s): CVE-2022-40303, CVE-2022-40304
Details: * SECURITY UPDATE: Integer overflows with XML_PARSE_HUGE - debian/patches/CVE-2022-40303.patch: Impose size limits when XML_PARSE_HUGE is set and add length checks to core parser functions - CVE-2022-40303 * SECURITY UPDATE: Dict corruption caused by entity reference cycles - debian/patches/CVE-2022-40304.patch: Stop storing entity content, orig, ExternalID and SystemID in a dict since these values are unlikely to occur multiple times in a document, so they shouldn't have been stored in a dict in the first place - CVE-2022-40304
Affected packages
Package
Name: libxml2
Purl: pkg:deb/tuxcare/libxml2?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
