xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libxmlsec1",
"binary_version": "1.2.18-2ubuntu1+esm1"
},
{
"binary_name": "libxmlsec1-dev",
"binary_version": "1.2.18-2ubuntu1+esm1"
},
{
"binary_name": "libxmlsec1-gcrypt",
"binary_version": "1.2.18-2ubuntu1+esm1"
},
{
"binary_name": "libxmlsec1-gnutls",
"binary_version": "1.2.18-2ubuntu1+esm1"
},
{
"binary_name": "libxmlsec1-nss",
"binary_version": "1.2.18-2ubuntu1+esm1"
},
{
"binary_name": "libxmlsec1-openssl",
"binary_version": "1.2.18-2ubuntu1+esm1"
},
{
"binary_name": "xmlsec1",
"binary_version": "1.2.18-2ubuntu1+esm1"
}
]
}
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libxmlsec1",
"binary_version": "1.2.20-2ubuntu4+esm1"
},
{
"binary_name": "libxmlsec1-dev",
"binary_version": "1.2.20-2ubuntu4+esm1"
},
{
"binary_name": "libxmlsec1-gcrypt",
"binary_version": "1.2.20-2ubuntu4+esm1"
},
{
"binary_name": "libxmlsec1-gnutls",
"binary_version": "1.2.20-2ubuntu4+esm1"
},
{
"binary_name": "libxmlsec1-nss",
"binary_version": "1.2.20-2ubuntu4+esm1"
},
{
"binary_name": "libxmlsec1-openssl",
"binary_version": "1.2.20-2ubuntu4+esm1"
},
{
"binary_name": "xmlsec1",
"binary_version": "1.2.20-2ubuntu4+esm1"
}
]
}