SUSE-SU-2021:14729-1
Dashboard / Vulnerabilities / SUSE-SU-2021:14729-1
SUSE-SU-2021:14729-1
Summary: Security update for libxml2
Details: This update for libxml2 fixes the following issues: Security issues fixed: - CVE-2021-3537: NULL pointer dereference in valid.c:xmlValidBuildAContentModel (bsc#1185698) - CVE-2021-3518: Fixed a use after free in xinclude.c:xmlXIncludeDoProcess (bsc#1185408). - CVE-2021-3517: Fixed a heap based buffer overflow in entities.c:xmlEncodeEntitiesInternal (bsc#1185410). - CVE-2021-3516: Fixed a use after free in xmlEncodeEntitiesInternal() in entities.c (bsc#1185409) - CVE-2020-24977: Fixed a global-buffer-overflow in xmlEncodeEntitiesInternal (bsc#1176179). - CVE-2019-20388: Fixed a memory leak in xmlSchemaPreRun (bsc#1161521). - CVE-2020-7595: Fixed an infinite loop in an EOF situation (bsc#1161517). - CVE-2019-19956: Fixed a memory leak in xmlParseBalancedChunkMemoryRecover (bsc#1159928).
References: https://www.suse.com/support/update/announcement/2021/suse-su-202114729-1/, https://bugzilla.suse.com/1159928, https://bugzilla.suse.com/1161517, https://bugzilla.suse.com/1161521, https://bugzilla.suse.com/1176179, https://bugzilla.suse.com/1185408, https://bugzilla.suse.com/1185409, https://bugzilla.suse.com/1185410, https://bugzilla.suse.com/1185698, https://www.suse.com/security/cve/CVE-2014-0191, https://www.suse.com/security/cve/CVE-2019-19956, https://www.suse.com/security/cve/CVE-2019-20388, https://www.suse.com/security/cve/CVE-2020-24977, https://www.suse.com/security/cve/CVE-2020-7595, https://www.suse.com/security/cve/CVE-2021-3516, https://www.suse.com/security/cve/CVE-2021-3517, https://www.suse.com/security/cve/CVE-2021-3518, https://www.suse.com/security/cve/CVE-2021-3537
Affected packages
Package
Name: libxml2
Purl: pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
