Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: libxml2 #1350

Closed
dongsupark opened this issue Feb 7, 2024 · 0 comments · Fixed by flatcar/scripts#1672
Closed

update: libxml2 #1350

dongsupark opened this issue Feb 7, 2024 · 0 comments · Fixed by flatcar/scripts#1672
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

dongsupark commented Feb 7, 2024

Name: libxml2
CVEs: CVE-2024-25062
CVSSs: 7.5
Action Needed: update to >= 2.11.7 or 2.12.5

Summary: An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.

refmap.gentoo: https://bugs.gentoo.org/923806

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant