Debian 10173 Published by

A libxml2 security update has been released for Debian GNU/Linux 8 Extended LTS to address a security issue.



ELA-436-1 libxml2 security update

Package libxml2
Version 2.9.1+dfsg1-5+deb8u11
Related CVEs CVE-2021-3541

An issue has been found in libxml2, the GNOME XML library.

This issue is called “Parameter Laughs”-attack and is related to parameter entities expansion. It is similar to the “Billion Laughs”-attacks found earlier in libexpat. More information can be found at [1]

[1] https://blog.hartwork.org/posts/cve-2021-3541-parameter-laughs-fixed-in-libxml2-2-9-11/

For Debian 8 jessie, these problems have been fixed in version 2.9.1+dfsg1-5+deb8u11.

We recommend that you upgrade your libxml2 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-436-1 libxml2 security update