UbuntuUpdates.org

Package "libxml2"

Name: libxml2

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GNOME XML library - Python3 bindings

Latest version: 2.9.14+dfsg-1.3ubuntu3.1
Release: noble (24.04)
Level: updates
Repository: universe

Links



Other versions of "libxml2" in Noble

Repository Area Version
base universe 2.9.14+dfsg-1.3ubuntu3
base main 2.9.14+dfsg-1.3ubuntu3
security main 2.9.14+dfsg-1.3ubuntu3.1
security universe 2.9.14+dfsg-1.3ubuntu3.1
updates main 2.9.14+dfsg-1.3ubuntu3.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.9.14+dfsg-1.3ubuntu3.1 2025-01-29 22:07:20 UTC

  libxml2 (2.9.14+dfsg-1.3ubuntu3.1) noble-security; urgency=medium

  * SECURITY UPDATE: use-after-free in xmlXIncludeAddNode
    - debian/patches/CVE-2022-49043.patch: fix UaF in xinclude.c.
    - CVE-2022-49043
  * SECURITY UPDATE: buffer overread in xmllint
    - debian/patches/CVE-2024-34459.patch: fix buffer issue when using
      htmlout option in xmllint.c.
    - CVE-2024-34459

 -- Marc Deslauriers <email address hidden> Tue, 28 Jan 2025 08:19:16 -0500

CVE-2022-49043 xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
CVE-2024-34459 An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result



About   -   Send Feedback to @ubuntu_updates