ELA-280-1 libxml2 security update

denial of service

2020-09-08
Packagelibxml2
Version2.9.1+dfsg1-5+deb8u9
Related CVEs CVE-2017-8872 CVE-2019-20388 CVE-2020-7595 CVE-2020-24977

Several security vulnerabilities were corrected in libxml2, the GNOME XML library.

CVE-2017-8872

Global buffer-overflow in the htmlParseTryOrFinish function.

CVE-2019-20388

A memory leak was found in the xmlSchemaValidateStream function of libxml2.
Applications that use this library may be vulnerable to memory not being
freed leading to a denial of service.

CVE-2020-24977

Out-of-bounds read restricted to xmllint --htmlout.

CVE-2020-7595

Infinite loop in xmlStringLenDecodeEntities can cause a denial of service.

For Debian 8 jessie, these problems have been fixed in version 2.9.1+dfsg1-5+deb8u9.

We recommend that you upgrade your libxml2 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/