First published: Mon Apr 28 2025(Updated: )
USN-7467-1 fixed several vulnerabilities in libxml2. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that the libxml2 Python bindings incorrectly handled certain return values. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2025-32414) It was discovered that libxml2 incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2025-32415)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libxml2 | <2.9.4+dfsg1-6.1ubuntu1.9+esm3 | 2.9.4+dfsg1-6.1ubuntu1.9+esm3 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/python-libxml2 | <2.9.4+dfsg1-6.1ubuntu1.9+esm3 | 2.9.4+dfsg1-6.1ubuntu1.9+esm3 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/python3-libxml2 | <2.9.4+dfsg1-6.1ubuntu1.9+esm3 | 2.9.4+dfsg1-6.1ubuntu1.9+esm3 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/libxml2 | <2.9.3+dfsg1-1ubuntu0.7+esm8 | 2.9.3+dfsg1-1ubuntu0.7+esm8 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/python-libxml2 | <2.9.3+dfsg1-1ubuntu0.7+esm8 | 2.9.3+dfsg1-1ubuntu0.7+esm8 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-7467-2 addresses vulnerabilities in libxml2 that may allow for potential attacks through incorrectly handled return values.
To mitigate the vulnerabilities addressed in USN-7467-2, upgrade libxml2 and its related Python packages to the specified remedied version.
USN-7467-2 affects Ubuntu 16.04 LTS and Ubuntu 18.04 LTS with specific versions of libxml2 and its Python bindings.
The impacted packages include libxml2, python-libxml2, and python3-libxml2 in the specified vulnerable versions.
Yes, USN-7467-1 provided initial information about the vulnerabilities that USN-7467-2 updates.