Release Info

Advisory: CLSA-2022:1647254642

OS: Ubuntu 16.04 ELS

Public date: 2022-03-14 00:00:00

Project: libxml2

Version: 2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2

Errata link: https://errata.cloudlinux.com/ubuntu16-els/CLSA-2022-1647254642.html

Changelog

* SECURITY UPDATE: Use-after-free of ID and IDREF attributes - debian/patches/CVE-2022-23308.patch: Do not store empty or whitespace-only attributes in ID table - CVE-2022-23308

Update

Update command: apt-get update apt-get --only-upgrade install libxml2*

Packages list

libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_amd64.deb libxml2-dev_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_amd64.deb libxml2-doc_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_all.deb libxml2-utils_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_amd64.deb python-libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els2_amd64.deb

CVEs

CVE-2022-23308