REDHAT-BUG-1338703: Medium severity libxml2 vulnerability
A vulnerability was found in the libxml2 library. A heap-based buffer overread could happen in xmlDictAddString.
References:
https://bugzilla.gnome.org/showbug.cgi?id=758605
Upstream fix:
https://git.gnome.org/browse/libxml2/commit/?id=a820dbeac29d330bae4be05d9ecd939ad6b4aa33
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1338703?
The severity of REDHAT-BUG-1338703 is considered to be high due to the potential for a heap-based buffer overread in the libxml2 library.
How do I fix REDHAT-BUG-1338703?
To fix REDHAT-BUG-1338703, users should update to the latest version of the libxml2 library that incorporates the necessary patches.
What versions of libxml2 are affected by REDHAT-BUG-1338703?
Specific versions of libxml2 that are affected by REDHAT-BUG-1338703 are not detailed, so it is recommended to check the release notes for your distribution.
Is there a workaround for REDHAT-BUG-1338703?
Currently, no official workaround for REDHAT-BUG-1338703 has been provided, so applying the update is the best course of action.
What is libxml2 in the context of REDHAT-BUG-1338703?
Libxml2 is a software library used for parsing XML documents, and the vulnerability REDHAT-BUG-1338703 involves a flaw within this library.