{"id":"CLSA-2021-1640700710","summary":"Fix CVE(s): CVE-2021-3517, CVE-2021-3516, CVE-2020-24977, CVE-2021-3541, CVE-2021-3537, CVE-2021-3518, CVE-2019-20388, CVE-2017-8872","details":"\n   * SECURITY UPDATE: Out-of-bounds array access\n     - debian/patches/CVE-2021-3517.patch: Validate UTF8 in xmlEncodeEntities\n     - CVE-2021-3517\n   * SECURITY UPDATE: Use-after-free error\n     - debian/patches/CVE-2021-3518.patch: Fix use-after-free\n       with 'xmllint --xinclude --dropdtd'\n     - CVE-2021-3518\n   * SECURITY UPDATE: Null pointer dereference while parsing in recovery mode\n     - debian/patches/CVE-2021-3537.patch: Propagate error in\n       xmlParseElementChildrenContentDeclPriv\n     - CVE-2021-3537\n   * SECURITY UPDATE: Parser fix for the billion laugs attach\n     - debian/patches/CVE-2021-3541.patch: Fix parameter entities expansion\n       in xmlParserEntityCheck\n     - CVE-2021-3541\n   * SECURITY UPDATE: Miscalculation of available bytes when parsing\n     - debian/patches/CVE-2017-8872.patch: Free input buffer in xmlHaltParser\n     - CVE-2017-8872\n   * SECURITY UPDATE: Memory leak\n     - debian/patches/CVE-2019-20388.patch: Fix memory leak in\n       xmlSchemaValidateStream\n     - CVE-2019-20388\n   * SECURITY UPDATE: Out-of-bounds array access\n     - debian/patches/CVE-2020-24977.patch: Fix out-of-bounds read with\n       'xmllint --htmlout'\n     - CVE-2020-24977\n   * SECURITY UPDATE: Use-after-free error\n     - debian/patches/CVE-2021-3516.patch: Fix use-after-free\n       with 'xmllint --html --push'\n     - CVE-2021-3516","modified":"2026-06-04T10:04:16.189236674Z","published":"2021-12-28T14:11:50Z","upstream":["CVE-2017-8872","CVE-2019-20388","CVE-2020-24977","CVE-2021-3516","CVE-2021-3517","CVE-2021-3518","CVE-2021-3537","CVE-2021-3541"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16_04/CLSA-2021-1640700710"}],"affected":[{"package":{"name":"libxml2","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libxml2?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1640700710.json"}},{"package":{"name":"libxml2-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libxml2-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1640700710.json"}},{"package":{"name":"libxml2-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libxml2-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1640700710.json"}},{"package":{"name":"libxml2-utils","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libxml2-utils?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1640700710.json"}},{"package":{"name":"python-libxml2","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/python-libxml2?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1640700710.json"}}],"schema_version":"1.7.5"}