ALAS2023-2023-097


Amazon Linux 2023 Security Advisory: ALAS-2023-097
Advisory Release Date: 2023-02-17 20:47 Pacific
Advisory Updated Date: 2023-02-22 23:27 Pacific
Severity: Medium

Issue Overview:

An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. (CVE-2022-40303)

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. (CVE-2022-40304)


Affected Packages:

xmlsec1


Issue Correction:
Run dnf update xmlsec1 --releasever=2023.0.20230222 to update your system.

New Packages:
aarch64:
    xmlsec1-openssl-debuginfo-1.2.33-3.amzn2023.0.2.aarch64
    xmlsec1-openssl-1.2.33-3.amzn2023.0.2.aarch64
    xmlsec1-debugsource-1.2.33-3.amzn2023.0.2.aarch64
    xmlsec1-debuginfo-1.2.33-3.amzn2023.0.2.aarch64
    xmlsec1-openssl-devel-1.2.33-3.amzn2023.0.2.aarch64
    xmlsec1-1.2.33-3.amzn2023.0.2.aarch64
    xmlsec1-devel-1.2.33-3.amzn2023.0.2.aarch64

src:
    xmlsec1-1.2.33-3.amzn2023.0.2.src

x86_64:
    xmlsec1-openssl-debuginfo-1.2.33-3.amzn2023.0.2.x86_64
    xmlsec1-1.2.33-3.amzn2023.0.2.x86_64
    xmlsec1-debuginfo-1.2.33-3.amzn2023.0.2.x86_64
    xmlsec1-openssl-1.2.33-3.amzn2023.0.2.x86_64
    xmlsec1-openssl-devel-1.2.33-3.amzn2023.0.2.x86_64
    xmlsec1-devel-1.2.33-3.amzn2023.0.2.x86_64
    xmlsec1-debugsource-1.2.33-3.amzn2023.0.2.x86_64