UbuntuUpdates.org

Package "libxml2"

Name: libxml2

Description:

GNOME XML library

Latest version: 2.12.7+dfsg+really2.9.14-0.4ubuntu0.1
Release: plucky (25.04)
Level: security
Repository: main
Homepage: http://xmlsoft.org

Links


Download "libxml2"


Other versions of "libxml2" in Plucky

Repository Area Version
base main 2.12.7+dfsg+really2.9.14-0.4
base universe 2.12.7+dfsg+really2.9.14-0.4
security universe 2.12.7+dfsg+really2.9.14-0.4ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.12.7+dfsg+really2.9.14-0.4ubuntu0.1 2025-04-28 14:07:15 UTC

  libxml2 (2.12.7+dfsg+really2.9.14-0.4ubuntu0.1) plucky-security; urgency=medium

  * SECURITY UPDATE: OOB access in python API
    - debian/patches/CVE-2025-32414-pre1.patch: fix SAX driver with
      character streams in python/drv_libxml2.py.
    - debian/patches/CVE-2025-32414-1.patch: read at most len/4 characters
      in python/libxml.c.
    - debian/patches/CVE-2025-32414-2.patch: add a test in
      python/tests/Makefile.am, python/tests/unicode.py.
    - CVE-2025-32414
  * SECURITY UPDATE: heap under-read in xmlSchemaIDCFillNodeTables
    - debian/patches/CVE-2025-32415.patch: fix heap buffer overflow in
      xmlSchemaIDCFillNodeTables in xmlschemas.c.
    - CVE-2025-32415

 -- Marc Deslauriers <email address hidden> Thu, 24 Apr 2025 14:42:32 -0400

CVE-2025-32414 In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect
CVE-2025-32415 In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a



About   -   Send Feedback to @ubuntu_updates