Amazon Linux 2023 Security Advisory: ALAS-2023-097
Advisory Release Date: 2023-02-17 20:47 Pacific
Advisory Updated Date: 2023-02-22 23:27 Pacific
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. (CVE-2022-40303)
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. (CVE-2022-40304)
Affected Packages:
xmlsec1
Issue Correction:
Run dnf update xmlsec1 --releasever=2023.0.20230222 to update your system.
aarch64:
xmlsec1-openssl-debuginfo-1.2.33-3.amzn2023.0.2.aarch64
xmlsec1-openssl-1.2.33-3.amzn2023.0.2.aarch64
xmlsec1-debugsource-1.2.33-3.amzn2023.0.2.aarch64
xmlsec1-debuginfo-1.2.33-3.amzn2023.0.2.aarch64
xmlsec1-openssl-devel-1.2.33-3.amzn2023.0.2.aarch64
xmlsec1-1.2.33-3.amzn2023.0.2.aarch64
xmlsec1-devel-1.2.33-3.amzn2023.0.2.aarch64
src:
xmlsec1-1.2.33-3.amzn2023.0.2.src
x86_64:
xmlsec1-openssl-debuginfo-1.2.33-3.amzn2023.0.2.x86_64
xmlsec1-1.2.33-3.amzn2023.0.2.x86_64
xmlsec1-debuginfo-1.2.33-3.amzn2023.0.2.x86_64
xmlsec1-openssl-1.2.33-3.amzn2023.0.2.x86_64
xmlsec1-openssl-devel-1.2.33-3.amzn2023.0.2.x86_64
xmlsec1-devel-1.2.33-3.amzn2023.0.2.x86_64
xmlsec1-debugsource-1.2.33-3.amzn2023.0.2.x86_64