USN-7215-1: libxml2 vulnerability
Published Jan 16, 2025
·Updated
Xisco Fauli discovered that libxml2 incorrectly handled custom SAX handlers. A remote attacker could possibly use this issue to perform XML External Entity (XXE) attacks.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/libxml2<2.12.7+dfsg-3ubuntu0.1
2.12.7+dfsg-3ubuntu0.1
Ubuntu Ubuntu=24.10
Event History
Jan 16, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7215-1?
The severity of USN-7215-1 is classified as a medium risk due to the potential for XML External Entity (XXE) attacks.
2
How do I fix USN-7215-1?
To fix USN-7215-1, you should update the libxml2 package to version 2.12.7+dfsg-3ubuntu0.1 or later.
3
What systems are affected by USN-7215-1?
USN-7215-1 affects Ubuntu 24.10 installations that utilize the libxml2 package.
4
What types of attacks can be executed due to USN-7215-1?
A remote attacker could exploit USN-7215-1 to perform XML External Entity (XXE) attacks, potentially leading to sensitive data exposure.
5
Who discovered the vulnerability in USN-7215-1?
The vulnerability in USN-7215-1 was discovered by security researcher Xisco Fauli.