REDHAT-BUG-1338686: Medium severity libxml2 vulnerability
A vulnerability was found in the libxml2 library. A maliciously crafted file could cause the application to crash due to a heap-based buffer underread in xmlParseName.
References:
https://bugzilla.gnome.org/showbug.cgi?id=759573
Upstream fix:
https://git.gnome.org/browse/libxml2/commit/?id=00906759053986b8079985644172085f74331f83
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1338686?
The severity of REDHAT-BUG-1338686 is considered high due to the potential for a heap-based buffer underread.
How do I fix REDHAT-BUG-1338686?
To fix REDHAT-BUG-1338686, update the libxml2 library to the latest version as recommended in the vendor's advisories.
What causes the vulnerability in REDHAT-BUG-1338686?
The vulnerability in REDHAT-BUG-1338686 is caused by improper handling of a maliciously crafted file which can lead to a crash.
What are the potential impacts of REDHAT-BUG-1338686?
The potential impacts of REDHAT-BUG-1338686 include application crashes and possible denial of service.
Which software is affected by REDHAT-BUG-1338686?
The software affected by REDHAT-BUG-1338686 includes the GNOME libxml2 library.