REDHAT-BUG-2358121: Medium severity Gnome libxml2 vulnerability
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2358121?
The severity of REDHAT-BUG-2358121 is critical due to out-of-bounds memory access risks.
How do I fix REDHAT-BUG-2358121?
To fix REDHAT-BUG-2358121, upgrade libxml2 to version 2.14.2 or later.
What versions of libxml2 are affected by REDHAT-BUG-2358121?
Libxml2 versions before 2.13.8 and from 2.14.0 to 2.14.2 are affected by REDHAT-BUG-2358121.
What is the cause of REDHAT-BUG-2358121?
REDHAT-BUG-2358121 is caused by an incorrect return value resulting in out-of-bounds access in the Python API.
Is the Python API for libxml2 safe in all versions?
No, the Python API for libxml2 is not safe in versions before 2.13.8 and between 2.14.0 and 2.14.2 due to REDHAT-BUG-2358121.