- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202210-39
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: libxml2: Multiple Vulnerabilities
Date: October 31, 2022
Bugs: #877149
ID: 202210-39
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been found in libxml2, the worst of which
could result in arbitrary code execution.
Background
==========
libxml2 is the XML C parser and toolkit developed for the GNOME project.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-libs/libxml2 < 2.10.3 >= 2.10.3
Description
===========
Multiple vulnerabilities have been discovered in libxml2. Please review
the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All libxml2 users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/libxml2-2.10.3"
References
==========
[ 1 ] CVE-2022-40303
https://nvd.nist.gov/vuln/detail/CVE-2022-40303
[ 2 ] CVE-2022-40304
https://nvd.nist.gov/vuln/detail/CVE-2022-40304
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202210-39
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmNgLwQACgkQFMQkOaVy +9kvkxAAjUZToM5TENeJkbt9GygxxHHSHD6apLXYLoGjQv3FRDeVy31UERFMLaXz edxnNsQS6Tv2OZcaRGAR/LcMNAMcY9jVmT4eVyn3mjrbvWQohqgOptvXkmjfMHYA eYFPOhZ5VgpSW1UHWk1P7N59JKbekH3hIFpgJme//uY1CIUUD88TPOFthr71O7CK oZ5pRO4pt2+MO/G4Wj2nXm0XjxZMhmuPXIlqjuzGeRqJO2uhCIL9huAp7sOlOwf8 NQ/4N52GY3awIVSD1jaP4Q0OZyC9uTCgRhPEdO7I1GCEJo0IUlA6SrzqYVJ+ZkrP XbkvoltYNNKlni8qU1qx5Oy9cPI5wI0o+P5TNdEG7T353zAXKY8XSN21TY8TU1Cr lGj8Utb0sMM/ACnwlKizO+mFYURnETKuE/cBsFcY7q0akpp6YKNAX9Kg7OOUiRsG XA57SmJo119E6LZgrLu68OMAX48YzG0EDAzVVJqdMMvklpq1EB1rOfTrry0DvZE4 qd249XQW2SMBZLRxSmZarYwNd16Wi+krY3peLaiOgfb2VLtxh+T+wTkTgGx0A8F8 k1ziLMWXKKaKSBjuz/3CXqmO2iKATSeOawi4paVjAJ6Z4qXVniNFcvIRvI5cQdKs zbXBBivD5JQWCMrNMCSGmZm/fQ6QfT+KG6PLCcHPllMzesO7zL8=
=z87X
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)