libxml2-2.9.7-8.el8

エラータID: AXSA:2020-1001:04

Release date: 
Sunday, December 20, 2020 - 02:14
Subject: 
libxml2-2.9.7-8.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The libxml2 library is a development toolbox providing the implementation of various XML standards.

Security Fix(es):

* libxml2: memory leak in xmlParseBalancedChunkMemoryRecover in parser.c (CVE-2019-19956)

* libxml2: memory leak in xmlSchemaPreRun in xmlschemas.c (CVE-2019-20388)

* libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations (CVE-2020-7595)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2019-19956
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
CVE-2019-20388
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
CVE-2020-7595
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libxml2-2.9.7-8.el8.src.rpm
    MD5: f6c8ba698a46b6e834a30277de0d50ca
    SHA-256: 16ac95795bb7982e8d70686560f773085e6ad9af042a358a0c41add71b6aa043
    Size: 5.21 MB

Asianux Server 8 for x86_64
  1. libxml2-2.9.7-8.el8.x86_64.rpm
    MD5: 9ee6fa23d61144a5d86dfd99288b3c33
    SHA-256: d9a51888621999580235589735310a3da444270ae9de9988210ebb5357c57229
    Size: 694.72 kB
  2. libxml2-devel-2.9.7-8.el8.x86_64.rpm
    MD5: 659dc10e48722e93a72d06a68935f827
    SHA-256: f5ecf5c02f283aaf3dd907563a4c1f59af2c1934ac790ffce9bfc821367d90ce
    Size: 1.04 MB
  3. python3-libxml2-2.9.7-8.el8.x86_64.rpm
    MD5: 811305273e73ec06c842e0845345a0ff
    SHA-256: 53fd1b6e196b7975cb483c279e3a69586b2d6f3c8dcea356e999c13fa94b1314
    Size: 235.63 kB
  4. libxml2-2.9.7-8.el8.i686.rpm
    MD5: 1c85dfb16f046c1574123cf2215f1b7b
    SHA-256: e8186e5eeb0539793fae3134a9f36cc1110380235c056fc9f5d80c8dd6c3add2
    Size: 739.70 kB
  5. libxml2-devel-2.9.7-8.el8.i686.rpm
    MD5: 394627426443d92488ab1bb3eaa35a72
    SHA-256: 62d7b6c5e1fab6b50525afe04429b2814582373dd5eb3e80016c6e070d2bf5e5
    Size: 1.04 MB