REDHAT-BUG-1281930: Low severity libxml2 vulnerability
An out-of-bounds heap read in xmlParseXMLDecl happens when a file containing unfinished xml declaration, e.g. <?xml versionencoding="ISO88598", is followed by 0xff byte.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=751631
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=709a952110e98621c9b78c4f26462a9d8333102e
Out-of-bounds heap read also occurs in xmlParseXMLDecl when file contains unterminated encoding value.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=751603
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=9aa37588ee78a06ca1379a9d9356eab16686099c
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1281930?
The severity of REDHAT-BUG-1281930 is classified as a high-risk vulnerability due to the potential for exploitation.
How do I fix REDHAT-BUG-1281930?
To fix REDHAT-BUG-1281930, update to the latest version of libxml2 that addresses this out-of-bounds heap read issue.
What software is affected by REDHAT-BUG-1281930?
The affected software for REDHAT-BUG-1281930 is GNOME's libxml2.
What causes the vulnerability REDHAT-BUG-1281930?
The vulnerability REDHAT-BUG-1281930 is caused by an out-of-bounds heap read during XML parsing when encountering an unfinished XML declaration.
Is there a known exploit for REDHAT-BUG-1281930?
As of now, there are no public exploits known for REDHAT-BUG-1281930, but the potential for exploitation exists.