]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
libxml2: Fix CVE-2023-39615
authorSoumya Sambu <soumya.sambu@windriver.com>
Thu, 7 Sep 2023 09:47:55 +0000 (09:47 +0000)
committerSteve Sakoman <steve@sakoman.com>
Tue, 12 Sep 2023 22:47:53 +0000 (12:47 -1000)
commit9a2ad95caffae37014fa27d9b20d45f9779d0fbf
tree5c8b8c15037c61332bb59e5b86fee1c558b1ce50
parentebbdbb68a7804accd5430dd05f7899599ddbacd8
libxml2: Fix CVE-2023-39615

Xmlsoft Libxml2 v2.11.0 was discovered to contain a global buffer overflow via
the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability
allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML
file.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-39615

Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-core/libxml/libxml2/CVE-2023-39615-0001.patch [new file with mode: 0644]
meta/recipes-core/libxml/libxml2/CVE-2023-39615-0002.patch [new file with mode: 0644]
meta/recipes-core/libxml/libxml2_2.9.14.bb