]> code.ossystems Code Review - openembedded-core.git/commit
libxml2: fix CVE-2021-3541
authorSteve Sakoman <steve@sakoman.com>
Wed, 21 Jul 2021 17:12:14 +0000 (07:12 -1000)
committerSteve Sakoman <steve@sakoman.com>
Mon, 26 Jul 2021 14:38:50 +0000 (04:38 -1000)
commit1699293a7011797895c284d6ad664c66badba426
tree97dfe1176ccb275c43c5a60b03558ac982f79482
parent55140153e66f13a2d8a673a48f6c21e293415e56
libxml2: fix CVE-2021-3541

A flaw was found in libxml2. Exponential entity expansion attack
is possible bypassing all existing protection mechanisms and leading
to denial of service.

https://nvd.nist.gov/vuln/detail/CVE-2021-3541
CVE: 2021-3541

Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-core/libxml/libxml2/CVE-2021-3541.patch [new file with mode: 0644]
meta/recipes-core/libxml/libxml2_2.9.10.bb