Mageia 2020-0101: libxml2_2 security update
Updated libxml2 packages fix security vulnerabilities: xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak (CVE-2019-20388).
Summary
Updated libxml2 packages fix security vulnerabilities:
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an
xmlSchemaValidateStream memory leak (CVE-2019-20388).
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite
loop in a certain end-of-file situation (CVE-2020-7595).
References
- https://bugs.mageia.org/show_bug.cgi?id=26222
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20388
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7595
Resolution
MGASA-2020-0101 - Updated libxml2_2 packages fix security vulnerabilities
SRPMS
- 7/core/libxml2-2.9.9-2.3.mga7