REDHAT-BUG-1281879: Buffer Overflow
Heap-based buffer overflow was found in xmlParseXmlDecl. When conversion failure happens, parser continues to extract more errors which may lead to unexpected behaviour.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=756527
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=afd27c21f6b36e22682b7da20d726bce2dcb2f43
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1281879?
The severity of REDHAT-BUG-1281879 is high due to the potential for a heap-based buffer overflow.
What types of applications are affected by REDHAT-BUG-1281879?
The affected software for REDHAT-BUG-1281879 includes GNOME's libxml2 library.
How do I fix REDHAT-BUG-1281879?
To fix REDHAT-BUG-1281879, update your libxml2 to the latest version that contains the security patch.
What causes the vulnerability in REDHAT-BUG-1281879?
The vulnerability in REDHAT-BUG-1281879 is caused by a heap-based buffer overflow during XML parsing under certain error conditions.
Can REDHAT-BUG-1281879 lead to system compromise?
Yes, REDHAT-BUG-1281879 can potentially lead to system compromise due to unexpected behavior caused by the buffer overflow.