First published: Mon Jan 23 2023(Updated: )
The libxml2 library is a development toolbox providing the implementation of various XML standards.<br>Security Fix(es):<br><li> libxml2: integer overflows with XML_PARSE_HUGE (CVE-2022-40303)</li> <li> libxml2: dict corruption caused by entity reference cycles (CVE-2022-40304)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libxml2 | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2 | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-debuginfo | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-debuginfo | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-debugsource | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-debugsource | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-devel | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-devel | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/python3-libxml2 | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/python3-libxml2-debuginfo | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/python3-libxml2-debuginfo | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/python3-libxml2 | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2 | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-debuginfo | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-debugsource | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2-devel | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/python3-libxml2 | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/python3-libxml2-debuginfo | <2.9.13-3.el9_1 | 2.9.13-3.el9_1 |
redhat/libxml2 | <2.9.13-3.el9_1.aa | 2.9.13-3.el9_1.aa |
redhat/libxml2-debuginfo | <2.9.13-3.el9_1.aa | 2.9.13-3.el9_1.aa |
redhat/libxml2-debugsource | <2.9.13-3.el9_1.aa | 2.9.13-3.el9_1.aa |
redhat/libxml2-devel | <2.9.13-3.el9_1.aa | 2.9.13-3.el9_1.aa |
redhat/python3-libxml2 | <2.9.13-3.el9_1.aa | 2.9.13-3.el9_1.aa |
redhat/python3-libxml2-debuginfo | <2.9.13-3.el9_1.aa | 2.9.13-3.el9_1.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:0338 is classified as moderate.
To fix RHSA-2023:0338, you should update to libxml2 version 2.9.13-3.el9_1 or later.
RHSA-2023:0338 addresses CVE-2022-40303 and CVE-2022-40304 related to integer overflows and dict corruption.
Affected packages include libxml2, libxml2-debuginfo, libxml2-devel, and python3-libxml2 among others.
RHSA-2023:0338 impacts the libxml2 library which is used for parsing XML documents.