Gentoo Archives: gentoo-announce

From: John Helmert III <ajak@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202107-05 ] libxml2: Multiple vulnerabilities
Date: Tue, 06 Jul 2021 08:29:36
Message-Id: YOPL5MngUmIIfGeY@sol.nexus.lan
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202107-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: libxml2: Multiple vulnerabilities
9 Date: July 06, 2021
10 Bugs: #749849, #790002
11 ID: 202107-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in libxml2, the worst of which
19 could result in a Denial of Service condition.
20
21 Background
22 ==========
23
24 libxml2 is the XML (eXtended Markup Language) C parser and toolkit
25 initially developed for the GNOME project.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 dev-libs/libxml2 < 2.9.11 >= 2.9.11
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in libxml2. Please review
39 the CVE identifiers referenced below for details.
40
41 Impact
42 ======
43
44 A remote attacker could entice a user to process a specially crafted
45 XML document using an application linked against libxml2, possibly
46 resulting in a Denial of Service condition or obtaining sensitive
47 information.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All libxml2 users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=dev-libs/libxml2-2.9.12-r3"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2020-24977
66 https://nvd.nist.gov/vuln/detail/CVE-2020-24977
67 [ 2 ] CVE-2021-3516
68 https://nvd.nist.gov/vuln/detail/CVE-2021-3516
69 [ 3 ] CVE-2021-3517
70 https://nvd.nist.gov/vuln/detail/CVE-2021-3517
71 [ 4 ] CVE-2021-3518
72 https://nvd.nist.gov/vuln/detail/CVE-2021-3518
73 [ 5 ] CVE-2021-3537
74 https://nvd.nist.gov/vuln/detail/CVE-2021-3537
75 [ 6 ] CVE-2021-3541
76 https://nvd.nist.gov/vuln/detail/CVE-2021-3541
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 https://security.gentoo.org/glsa/202107-05
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users' machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 https://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2021 Gentoo Foundation, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature