USN-4991-1
Vulnerability Summary
Timeline
Description
libxml2 vulnerabilities Yunho Kim discovered that libxml2 incorrectly handled certain error conditions. A remote attacker could exploit this with a crafted XML file to cause a denial of service, or possibly cause libxml2 to expose sensitive information. This issue only affected Ubuntu 14.04 ESM, and Ubuntu 16.04 ESM. (CVE-2017-8872) Zhipeng Xie discovered that libxml2 incorrectly handled certain XML schemas. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 LTS. (CVE-2019-20388) It was discovered that libxml2 incorrectly handled invalid UTF-8 input. A remote attacker could possibly exploit this with a crafted XML file to cause libxml2 to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-24977) It was discovered that libxml2 incorrectly handled invalid UTF-8 input. A remote attacker could possibly exploit this with a crafted XML file to cause libxml2 to crash, resulting in a denial of service. (CVE-2021-3517) It was discovered that libxml2 did not properly handle certain crafted XML files. A local attacker could exploit this with a crafted input to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-3516, CVE-2021-3518) It was discovered that libxml2 incorrectly handled error states. A remote attacker could exploit this with a crafted XML file to cause libxml2 to crash, resulting in a denial of service. (CVE-2021-3537) Sebastian Pipping discovered that libxml2 did not properly handle certain crafted XML files. A remote attacker could exploit this with a crafted XML file to cause libxml2 to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-3541)
Affected Systems
- ubuntu•libxml2
< 2.9.1+dfsg1-3ubuntu4.13+esm2 | < 2.9.3+dfsg1-1ubuntu0.7+esm1 | < 2.9.4+dfsg1-6.1ubuntu1.4 | < 2.9.10+dfsg-5ubuntu0.20.04.1
References (9)
- https://ubuntu.com/security/notices/USN-4991-1
- https://ubuntu.com/security/CVE-2017-8872
- https://ubuntu.com/security/CVE-2019-20388
- https://ubuntu.com/security/CVE-2020-24977
- https://ubuntu.com/security/CVE-2021-3516
- https://ubuntu.com/security/CVE-2021-3517
- https://ubuntu.com/security/CVE-2021-3518
- https://ubuntu.com/security/CVE-2021-3537
- https://ubuntu.com/security/CVE-2021-3541