Xisco Fauli discovered that libxml2 incorrectly handled custom SAX handlers. A remote attacker could possibly use this issue to perform XML External Entity (XXE) attacks.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2.12.7+dfsg-3ubuntu0.1", "binary_name": "libxml2" }, { "binary_version": "2.12.7+dfsg-3ubuntu0.1", "binary_name": "libxml2-dbgsym" }, { "binary_version": "2.12.7+dfsg-3ubuntu0.1", "binary_name": "libxml2-dev" }, { "binary_version": "2.12.7+dfsg-3ubuntu0.1", "binary_name": "libxml2-doc" }, { "binary_version": "2.12.7+dfsg-3ubuntu0.1", "binary_name": "libxml2-utils" }, { "binary_version": "2.12.7+dfsg-3ubuntu0.1", "binary_name": "libxml2-utils-dbgsym" }, { "binary_version": "2.12.7+dfsg-3ubuntu0.1", "binary_name": "python3-libxml2" }, { "binary_version": "2.12.7+dfsg-3ubuntu0.1", "binary_name": "python3-libxml2-dbgsym" } ] }