[Debian] Medium CVE: CVE-2023-28484/CVE-2023-29469: libxml2: multiple CVEs

Bug #2021462 reported by Yue Tao
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
Medium
Li Zhou

Bug Description

CVE-2023-28484: https://nvd.nist.gov/vuln/detail/CVE-2023-28484

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.

CVE-2023-29469: https://nvd.nist.gov/vuln/detail/CVE-2023-29469

An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '\0' value).

Base Score: Medium

References:

https://www.debian.org/security/2023/dsa-5391

https://security-tracker.debian.org/tracker/CVE-2023-28484

https://security-tracker.debian.org/tracker/CVE-2023-29469

['libxml2-dev_2.9.10+dfsg-6.7+deb11u3_amd64.deb===>libxml2-dev_2.9.10+dfsg-6.7+deb11u4_amd64.deb', 'libxml2-utils_2.9.10+dfsg-6.7+deb11u3_amd64.deb===>libxml2-utils_2.9.10+dfsg-6.7+deb11u4_amd64.deb', 'libxml2_2.9.10+dfsg-6.7+deb11u3_amd64.deb===>libxml2_2.9.10+dfsg-6.7+deb11u4_amd64.deb']

CVE References

Yue Tao (wrytao)
tags: added: stx.9.0
tags: added: stx.security
Changed in starlingx:
status: New → Triaged
importance: Undecided → Medium
Li Zhou (lzhou2)
Changed in starlingx:
assignee: nobody → Li Zhou (lzhou2)
Revision history for this message
Ghada Khalil (gkhalil) wrote :
Changed in starlingx:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.