Release Info

Advisory: CLSA-2022:1670522760

OS: CloudLinux 6 ELS

Public date: 2022-12-08 00:00:00

Project: libxml2

Version: 2.7.6-21.el6_8.1.tuxcare.els3

Errata link: https://errata.tuxcare.com/els_os/cloudlinux6els/CLSA-2022-1670522760.html

Changelog

- CVE-2022-40303: fix integer overflows with XML_PARSE_HUGE - CVE-2022-40304: fix dict corruption caused by entity reference cycles

Update

Update command: yum update libxml2*

Packages list

libxml2-2.7.6-21.el6_8.1.tuxcare.els3.i686.rpm libxml2-2.7.6-21.el6_8.1.tuxcare.els3.x86_64.rpm libxml2-devel-2.7.6-21.el6_8.1.tuxcare.els3.i686.rpm libxml2-devel-2.7.6-21.el6_8.1.tuxcare.els3.x86_64.rpm libxml2-python-2.7.6-21.el6_8.1.tuxcare.els3.x86_64.rpm libxml2-static-2.7.6-21.el6_8.1.tuxcare.els3.x86_64.rpm

CVEs

CVE-2022-40304
CVE-2022-40303