CLSA-2021-1640700669

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux6els/CLSA-2021-1640700669.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2021-1640700669
Upstream
Published
2021-12-28T14:11:09Z
Modified
2026-06-01T00:33:24.410649907Z
Summary
Fixed 8 CVEs in libxml2
Details
  • CVE-2021-3517.patch: validate UTF8 in xmlEncodeEntities
  • CVE-2021-3518.patch: fix user-after-free with 'xmllint --xinclude --dropdtd'
  • CVE-2021-3537.patch: propagate error in xmlParseElementChildrenContentDeclPriv
  • CVE-2021-3541.patch: parser fix for the billion laughs attack
  • CVE-2021-3516.patch: fix use-after-free with 'xmllint --html --push'
  • CVE-2017-8872.patch: free input buffer in xmlHaltParser
  • CVE-2019-20388.patch: fix memory leak in xmlSchemaValidateStream
  • CVE-2020-24977.patch: fix out-of-bounds read with 'xmllint --htmlout'
References

Affected packages

TuxCare:OracleLinux:6 / libxml2

Package

Name
libxml2
Purl
pkg:rpm/tuxcare/libxml2?distro=oraclelinux-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-21.0.1.el6_8.1.tuxcare.ol.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux6els/CLSA-2021-1640700669.json"

TuxCare:OracleLinux:6 / libxml2-devel

Package

Name
libxml2-devel
Purl
pkg:rpm/tuxcare/libxml2-devel?distro=oraclelinux-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-21.0.1.el6_8.1.tuxcare.ol.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux6els/CLSA-2021-1640700669.json"

TuxCare:OracleLinux:6 / libxml2-python

Package

Name
libxml2-python
Purl
pkg:rpm/tuxcare/libxml2-python?distro=oraclelinux-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-21.0.1.el6_8.1.tuxcare.ol.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux6els/CLSA-2021-1640700669.json"

TuxCare:OracleLinux:6 / libxml2-static

Package

Name
libxml2-static
Purl
pkg:rpm/tuxcare/libxml2-static?distro=oraclelinux-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-21.0.1.el6_8.1.tuxcare.ol.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux6els/CLSA-2021-1640700669.json"