Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in xmldom
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in xmldom
ID: USN-6102-1
Distribution: Ubuntu
Plattformen: Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 22.10
Datum: Mi, 24. Mai 2023, 23:20
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37616
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39353
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21366
https://launchpad.net/ubuntu/+source/node-xmldom/0.1.27+ds-1+deb10u2build0.20.04.1
Applikationen: xmldom

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============2750606757362712793==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="------------7WpRN0SY4PqO7U1vD1D0K7Ix"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------7WpRN0SY4PqO7U1vD1D0K7Ix
Content-Type: multipart/mixed;
boundary="------------FDJBWllCNviDBU2cdrs5n26L";
protected-headers="v1"
From: Amir Naseredini <amir.naseredini@canonical.com>
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <1bb37d5e-3acd-c334-2a8b-30a1e8bfce02@canonical.com>
Subject: [USN-6102-1] xmldom vulnerabilities

--------------FDJBWllCNviDBU2cdrs5n26L
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: base64

==========================================================================
Ubuntu Security Notice USN-6102-1
May 24, 2023

node-xmldom vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in xmldom.

Software Description:
- node-xmldom: A pure JavaScript W3C standard-based `DOMParser` and
`XMLSerializer` module.

Details:

It was discovered that xmldom incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause
unexpected syntactic changes during XML processing. This issue only affected
Ubuntu 20.04 LTS. (CVE-2021-21366)

It was discovered that xmldom incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-37616, CVE-2022-39353)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
node-xmldom 0.7.5-1ubuntu0.22.10.1

Ubuntu 22.04 LTS:
node-xmldom 0.7.5-1ubuntu0.22.04.1

Ubuntu 20.04 LTS:
node-xmldom 0.1.27+ds-1+deb10u2build0.20.04.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6102-1
CVE-2021-21366, CVE-2022-37616, CVE-2022-39353

Package Information:
https://launchpad.net/ubuntu/+source/node-xmldom/0.7.5-1ubuntu0.22.10.1
https://launchpad.net/ubuntu/+source/node-xmldom/0.7.5-1ubuntu0.22.04.1

https://launchpad.net/ubuntu/+source/node-xmldom/0.1.27+ds-1+deb10u2build0.20.04.1

--------------FDJBWllCNviDBU2cdrs5n26L--

--------------7WpRN0SY4PqO7U1vD1D0K7Ix
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmRt8vMFAwAAAAAACgkQVjg+NdFTuLLD
VwwA0twwpdl5849P5QCLntIr7jvK0ymg/r7DkXGyR5nFLujzerz7iv23OEsd9f7fHgsBsDw5fylP
mifkb8XEUkFDAAk+S6952ADvd41TFjpWjVMhPpB5qc+Z67fIwzSgk043/XzV9avH2ZRySXTP1nKw
tWhSo266ZL7/326utLtudBPA459eryBNlU4LXBNr7TSFYIIdog1zlBUjrqxou4g/Wjvt0P+hiQOk
0ZnggZ2pbobkGzKy4yGFw7MynvozDMt/+qiIAFZU1QZTIiduWeICj9zaC4XG6Q3uZB1pzm8A5SSY
2z+4Ozn1SIPKBoUFf0u+YcJ5tkOyh7AXeQcGsgkoUAdHlX87N6Cl0PjcaE+J/BSypHNtWm1UmG3r
QJnAXMxvvfcuP+CvnS4q001hVWw+bUnhww8QvNbw9fMnHNEpra4bMIepUwNsy4iGAidB1JDzanHD
FYSlWHrWKIE/AMLxhhsro0OzI3Ey58gFTOuoRpu3ofOhX/zymwda4/6+MIqp
=hUHs
-----END PGP SIGNATURE-----

--------------7WpRN0SY4PqO7U1vD1D0K7Ix--


--===============2750606757362712793==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============2750606757362712793==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung