Red Hat Bugzilla – Bug 1462203
CVE-2017-7375 libxml2: Missing validation for external entities in xmlParsePEReference
Last modified: 2018-07-18 11:24:31 EDT
Missing validation for external entities was found in xmlParsePEReference that can lead to XXE attack. Upstream bug (private at the moment): https://bugzilla.gnome.org/show_bug.cgi?id=780691 Android patch: https://android.googlesource.com/platform/external/libxml2/+/308396a55280f69ad4112d4f9892f4cbeff042aa References: https://source.android.com/security/bulletin/2017-06-01#libraries
Created libxml2 tracking bugs for this issue: Affects: fedora-all [bug 1462226] Created mingw-libxml2 tracking bugs for this issue: Affects: epel-7 [bug 1462227] Affects: fedora-all [bug 1462228]