Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: libxml2 #1118

Closed
dongsupark opened this issue Jul 17, 2023 · 1 comment
Closed

update: libxml2 #1118

dongsupark opened this issue Jul 17, 2023 · 1 comment
Labels
advisory security advisory security security concerns

Comments

@dongsupark
Copy link
Member

Name: libxml2
CVEs: no CVE, libxml2-20230428
CVSSs: n/a
Action Needed: update to >= libxml2 2.11.1

Summary:

  • Fix use-after-free in xmlParseContentInternal() (David Kilzer)
  • xmllint: Fix use-after-free with --maxmem
  • parser: Fix OOB read when formatting error message
  • entities: Rework entity amplification checks

refmap.gentoo: https://bugs.gentoo.org/905399

@dongsupark
Copy link
Member Author

PR flatcar/scripts#987 was merged. libxml2 2.11.4 will be included in the next Alpha.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory security security concerns
Projects
None yet
Development

No branches or pull requests

1 participant