REDHAT-BUG-1799786: Medium severity Gnome libxml2 vulnerability
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Reference and upstream commit: https://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1799786?
The severity of REDHAT-BUG-1799786 is considered high due to the potential for an infinite loop in the libxml2 parser leading to denial of service.
How do I fix REDHAT-BUG-1799786?
To fix REDHAT-BUG-1799786, update libxml2 to a version that has implemented the upstream commit addressing this vulnerability.
What software is affected by REDHAT-BUG-1799786?
The affected software for REDHAT-BUG-1799786 is libxml2 version 2.9.10.
What is the nature of the vulnerability in REDHAT-BUG-1799786?
The vulnerability in REDHAT-BUG-1799786 is an infinite loop that occurs in the xmlStringLenDecodeEntities function under certain end-of-file conditions.
Is there a known exploit for REDHAT-BUG-1799786?
As of now, there are no publicly disclosed exploits specifically targeting REDHAT-BUG-1799786.