[CLSA-2023:1682593947] Fix CVE(s): CVE-2023-29469, CVE-2023-28484
Type:
security
Severity:
Moderate
Release date:
2023-04-27 11:12:34 UTC
Description:
* SECURITY UPDATE: Null dereference - debian/patches/CVE-2023-28484.patch: Fix null-pointer-deref in xmlSchemaFixupComplexType - CVE-2023-28484 * SECURITY UPDATE: Fix a null pointer dereference - debian/patches/fix-null-ptr-deref.patch: use XML_SCHEMAS_ANYTYPE instead of a null pointer - CVE-2023-28484 * SECURITY UPDATE: Logic or memory errors - debian/patches/CVE-2023-29469.patch: check whether namelen is less than or equal to zero - CVE-2023-29469 * Add test suite - debian/patches/enable-building-tests.patch: enable building tests - debian/patches/fix-testapi.patch: fix buffer overflow in tests
Updated packages:
  • libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els6_amd64.deb
    sha:61cebb2c4dafef557fee29014572f367c5bf73a0
  • libxml2-dev_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els6_amd64.deb
    sha:2497c543ec1c9af6f042effaa079412b4ab7b4cf
  • libxml2-doc_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els6_all.deb
    sha:14f5a681839845d04d8cebd8c354bde0cbb25d6f
  • libxml2-utils_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els6_amd64.deb
    sha:4ef3032c43a3600670e85dff49e17dec50ca8428
  • python-libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els6_amd64.deb
    sha:3461a4a96e6ff491b19b068c3231a73a0908764a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.