Uploaded image for project: 'Puppet Agent'
  1. Puppet Agent
  2. PA-2337

Update libxml2 to 2.9.8 and add patches for CVEs

    XMLWordPrintable

Details

    • Bug
    • Status: Resolved
    • Normal
    • Resolution: Done
    • None
    • None
    • Security
    • Platform OS
    • Platform OS Kanban
    • Needs Assessment
    • Security Fix
    • This fixes security issues in libxml2 2.9.4 affected by CVE-2016-9318, CVE-2017-16932, CVE-2017-18258, CVE-2018-9251, CVE-2018-14404, and CVE-2018-14567.
    • Needs Assessment

    Description

      libxml2 2.9.8 has fixes for a number of security issues.

      In addition, there are two unreleased fixes that we'll need to pull in and apply as patches:

      https://gitlab.gnome.org/GNOME/libxml2/commit/a436374994c47b12d5de1b8b1d191a098fa23594
      https://gitlab.gnome.org/GNOME/libxml2/commit/2240fbf5912054af025fb6e01e26375100275e74

      Attachments

        Activity

          People

            enis.inan Enis Inan
            bradejr Rob Braden
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Zendesk Support