VYPR

rpm package

suse/libxml2-python&distro=SUSE Linux Enterprise Module for Python 3 15 SP4

pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP4

Vulnerabilities (2)

  • CVE-2023-45322Oct 6, 2023
    affected < 2.9.14-150400.5.25.1fixed 2.9.14-150400.5.25.1

    libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically ca

  • CVE-2023-39615Aug 29, 2023
    affected < 2.9.14-150400.5.22.1fixed 2.9.14-150400.5.22.1

    Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the prod