openSUSE-SU-2021:0764-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0764-1
openSUSE-SU-2021:0764-1
Summary: Security update for libxml2
Details: This update for libxml2 fixes the following issues: - CVE-2021-3537: NULL pointer dereference in valid.c:xmlValidBuildAContentModel (bsc#1185698) - CVE-2021-3518: Fixed a use after free in xinclude.c:xmlXIncludeDoProcess (bsc#1185408). - CVE-2021-3517: Fixed a heap based buffer overflow in entities.c:xmlEncodeEntitiesInternal (bsc#1185410). - CVE-2021-3516: Fixed a use after free in entities.c:xmlEncodeEntitiesInternal (bsc#1185409). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/32MGTWHTQRUPYHYIAVT6OVBDWQDI36DX/, https://bugzilla.suse.com/1185408, https://bugzilla.suse.com/1185409, https://bugzilla.suse.com/1185410, https://bugzilla.suse.com/1185698, https://www.suse.com/security/cve/CVE-2021-3516, https://www.suse.com/security/cve/CVE-2021-3517, https://www.suse.com/security/cve/CVE-2021-3518, https://www.suse.com/security/cve/CVE-2021-3537
Affected packages
Package
Name: libxml2
Purl: pkg:rpm/opensuse/libxml2&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
