Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2.9.13+dfsg-1ubuntu0.12",
"binary_name": "libxml2"
},
{
"binary_version": "2.9.13+dfsg-1ubuntu0.12",
"binary_name": "libxml2-utils"
},
{
"binary_version": "2.9.13+dfsg-1ubuntu0.12",
"binary_name": "python3-libxml2"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2.9.14+dfsg-1.3ubuntu3.8",
"binary_name": "libxml2"
},
{
"binary_version": "2.9.14+dfsg-1.3ubuntu3.8",
"binary_name": "libxml2-utils"
},
{
"binary_version": "2.9.14+dfsg-1.3ubuntu3.8",
"binary_name": "python3-libxml2"
}
]
}