Alpine: multiple libxml2 packages, multiple py3-libxml2 packages: security update to 2.9.3-r0 (deprecated)

high Tenable Self-Hosted Container Security Plugin ID 401038

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before
9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
(CVE-2016-1834)

- The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service
(heap-based buffer over-read) via a crafted XML document. (CVE-2016-1762)

- The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before
10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service
(heap-based buffer over-read) via a crafted XML document. (CVE-2016-1833)

- Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple
iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of service via a
crafted XML document. (CVE-2016-1835)

See Also

https://git.alpinelinux.org/aports/commit/?id=28ac3cd408bb8789a35497af052c6cb78bc14209

https://git.alpinelinux.org/aports/commit/?id=8aa7dd816ba978268e23e1e87cd0942e65be872c

Plugin Details

Severity: High

ID: 401038

Version: Revision 1.22

Type: Local

Published: 8/16/2023

Updated: 1/17/2024

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2016-1834

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2016-1835

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/30/2016

Vulnerability Publication Date: 2/12/2016

Reference Information

CVE: CVE-2016-1762, CVE-2016-1833, CVE-2016-1834, CVE-2016-1835, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, CVE-2016-1840, CVE-2016-2073, CVE-2016-3627, CVE-2016-3705, CVE-2016-4483

BID: 84992, 85059, 85267, 89854, 90013, 90691, 90696