[ubuntu/questing-proposed] libxml2 2.12.7+dfsg+really2.9.14-0.4ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Apr 30 17:00:38 UTC 2025


libxml2 (2.12.7+dfsg+really2.9.14-0.4ubuntu0.1) plucky-security; urgency=medium

  * SECURITY UPDATE: OOB access in python API
    - debian/patches/CVE-2025-32414-pre1.patch: fix SAX driver with
      character streams in python/drv_libxml2.py.
    - debian/patches/CVE-2025-32414-1.patch: read at most len/4 characters
      in python/libxml.c.
    - debian/patches/CVE-2025-32414-2.patch: add a test in
      python/tests/Makefile.am, python/tests/unicode.py.
    - CVE-2025-32414
  * SECURITY UPDATE: heap under-read in xmlSchemaIDCFillNodeTables
    - debian/patches/CVE-2025-32415.patch: fix heap buffer overflow in
      xmlSchemaIDCFillNodeTables in xmlschemas.c.
    - CVE-2025-32415

Date: 2025-04-24 20:06:34.191217+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libxml2/2.12.7+dfsg+really2.9.14-0.4ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list