[CLSA-2022:1647254642] Fix CVE(s): CVE-2022-23308
Type:
security
Severity:
moderate
Release date:
2022-03-14 10:44:02 UTC
Description:
* SECURITY UPDATE: Use-after-free of ID and IDREF attributes - debian/patches/CVE-2022-23308.patch: Do not store empty or whitespace-only attributes in ID table - CVE-2022-23308
Updated packages:
  • libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_amd64.deb
    sha:a4369faf1a6ed2b79abe1174660ab36b8152bccd
  • libxml2-dev_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_amd64.deb
    sha:435737ca8db3ed2c08ad120b0502073c8d0dbe8e
  • libxml2-doc_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_all.deb
    sha:2645c185fde26622ba5314e9f2224fee6d1b9157
  • libxml2-utils_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_amd64.deb
    sha:f5833f9c458a7714777523b76b842713552abe8d
  • python-libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_amd64.deb
    sha:c6d97594b9a5d32bce800075511ae35272156fc4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.