REDHAT-BUG-1338701: Medium severity libxml2 vulnerability
A vulnerability was found in the libxml2 library. The parser would fetch content of an external entity while not in validating mode.
References:
https://bugzilla.gnome.org/showbug.cgi?id=761430
Upstream fix:
https://git.gnome.org/browse/libxml2/commit/?id=b1d34de46a11323fccffa9fadeb33be670d602f5
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1338701?
The severity of REDHAT-BUG-1338701 is considered critical due to potential remote code execution risks.
How do I fix REDHAT-BUG-1338701?
To fix REDHAT-BUG-1338701, you should upgrade to the latest version of the libxml2 library that includes the security patch.
What systems are affected by REDHAT-BUG-1338701?
REDHAT-BUG-1338701 affects systems using the vulnerable versions of the libxml2 library.
Is there a workaround for REDHAT-BUG-1338701?
While there are no official workarounds for REDHAT-BUG-1338701, disabling external entity parsing may reduce risk.
What are the potential impacts of REDHAT-BUG-1338701?
The potential impacts of REDHAT-BUG-1338701 include unauthorized access to sensitive data and remote code execution vulnerabilities.