USN-7240-1: libxml2 vulnerabilities
It was discovered that libxml2 incorrectly handled certain memory operations. A remote attacker could use this issue to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-49043) It was discovered that the libxml2 xmllint tool incorrectly handled certain memory operations. If a user or automated system were tricked into running xmllint on a specially crafted xml file, a remote attacker could cause xmllint to crash, resulting in a denial of service. (CVE-2024-34459)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7240-1?
The severity of USN-7240-1 is critical, as it allows remote code execution and denial of service.
How do I fix USN-7240-1?
To fix USN-7240-1, update the libxml2 package to version 2.9.14+dfsg-1.3ubuntu3.1 or higher.
Which versions of libxml2 are affected by USN-7240-1?
Versions of libxml2 prior to 2.9.14+dfsg-1.3ubuntu3.1 for Ubuntu 24.04, 2.9.13+dfsg-1ubuntu0.5 for Ubuntu 22.04, and 2.9.10+dfsg-5ubuntu0.20.04.8 for Ubuntu 20.04 are affected.
Can USN-7240-1 lead to data breaches?
Yes, USN-7240-1 could potentially lead to data breaches due to remote code execution capabilities.
What is the main component affected by USN-7240-1?
The main component affected by USN-7240-1 is the libxml2 library, specifically its memory handling operations.