MGASA-2021-0474 - Updated xstream/xmlpull/mxparser packages fix security vulnerability

Publication date: 13 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0474.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-39139,
     CVE-2021-39140,
     CVE-2021-39141,
     CVE-2021-39144,
     CVE-2021-39145,
     CVE-2021-39146,
     CVE-2021-39147,
     CVE-2021-39148,
     CVE-2021-39149,
     CVE-2021-39150,
     CVE-2021-39151,
     CVE-2021-39152,
     CVE-2021-39153,
     CVE-2021-39154

Multiple security vulnerabilities have been discovered in XStream. See
references for details.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29512
- https://www.debian.org/lts/security/2021/dla-2769
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39139
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39140
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39141
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39144
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39145
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39146
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39147
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39148
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39149
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39150
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39151
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39152
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39153
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39154

SRPMS:
- 8/core/xstream-1.4.18-1.mga8
- 8/core/xmlpull-1.2.0-1.mga8
- 8/core/mxparser-1.2.2-1.mga8

Mageia 2021-0474: xstream/xmlpull/mxparser security update

Multiple security vulnerabilities have been discovered in XStream

Summary

Multiple security vulnerabilities have been discovered in XStream. See references for details.

References

- https://bugs.mageia.org/show_bug.cgi?id=29512

- https://www.debian.org/lts/security/2021/dla-2769

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39139

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39140

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39141

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39144

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39145

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39146

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39147

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39148

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39149

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39150

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39151

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39152

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39153

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39154

Resolution

MGASA-2021-0474 - Updated xstream/xmlpull/mxparser packages fix security vulnerability

SRPMS

- 8/core/xstream-1.4.18-1.mga8

- 8/core/xmlpull-1.2.0-1.mga8

- 8/core/mxparser-1.2.2-1.mga8

Severity
Publication date: 13 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0474.html
Type: security
CVE: CVE-2021-39139, CVE-2021-39140, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145, CVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149, CVE-2021-39150, CVE-2021-39151, CVE-2021-39152, CVE-2021-39153, CVE-2021-39154

Related News