[CLSA-2024:1708427829] Fix CVE(s): CVE-2024-25062
Type:
security
Severity:
Important
Release date:
2024-02-20 11:17:12 UTC
Description:
* SECURITY UPDATE: Use-after-free in xmlValidatePopElement() - debian/patches/CVE-2024-25062.patch: Fix use-after-free if XML Reader with DTD validation and XInclude expansion by not expanding XIncludes when backtracking - CVE-2024-25062
Updated packages:
  • libxml2_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els1_amd64.deb
    sha:c7b520634a9cd05149870078f9ebbec27ec6fe33
  • libxml2-dev_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els1_amd64.deb
    sha:c0cfa0fc23564dbf0cd6ea1679fdd584aef962a5
  • libxml2-doc_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els1_all.deb
    sha:1a84d218207ea5d6d646d0e4f0c6abe2de3fbe53
  • libxml2-utils_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els1_amd64.deb
    sha:a7429edeb39e7893250adf21aa19c1f05da78362
  • python-libxml2_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els1_amd64.deb
    sha:604016e1322fa6559c29f046b66ed51247ef0587
  • python3-libxml2_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els1_amd64.deb
    sha:c1f118827e38f07e2dd52ccfe23f892a06a5277e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.