USN-7215-1: libxml2 vulnerability
16 January 2025
libxml2 could be made to expose sensitive information over the network.
Releases
Packages
- libxml2 - GNOME XML library
Details
Xisco Fauli discovered that libxml2 incorrectly handled custom SAX
handlers. A remote attacker could possibly use this issue to perform XML
External Entity (XXE) attacks.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
In general, a standard system update will make all the necessary changes.