File _patchinfo of Package patchinfo.19429
<patchinfo incident="19429">
<issue tracker="bnc" id="1185410">VUL-0: CVE-2021-3517: libxml2: heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c</issue>
<issue tracker="bnc" id="1185408">VUL-0: CVE-2021-3518: libxml2: use-after-free in xmlXIncludeDoProcess() in xinclude.c</issue>
<issue tracker="bnc" id="1185409">VUL-0: CVE-2021-3516: libxml2: use-after-free in xmlEncodeEntitiesInternal() in entities.c</issue>
<issue tracker="cve" id="2021-3518"/>
<issue tracker="cve" id="2021-3516"/>
<issue tracker="cve" id="2021-3517"/>
<packager>pmonrealgonzalez</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for libxml2</summary>
<description>This update for libxml2 fixes the following issues:
- CVE-2021-3518: Fixed a use after free in xinclude.c:xmlXIncludeDoProcess (bsc#1185408).
- CVE-2021-3517: Fixed a heap based buffer overflow in entities.c:xmlEncodeEntitiesInternal (bsc#1185410).
- CVE-2021-3516: Fixed a use after free in entities.c:xmlEncodeEntitiesInternal (bsc#1185409).
</description>
</patchinfo>