- Issued:
- 2024-09-24
- Updated:
- 2024-09-24
RHBA-2024:6967 - Bug Fix Advisory
Synopsis
xmlsec1 bug fix update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for xmlsec1 is now available for Red Hat Enterprise Linux 8.
Description
XML Security Library is a C library based on LibXML2 and OpenSSL. The library was created with a goal to support major XML security standards "XML Digital Signature" and "XML Encryption".
Bug Fix(es):
- xmlsec1: Fix findings from static application security testing (SAST) (JIRA:RHEL-36185)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the update, all running applications that use the xmlsec1 library must be restarted for the update to take effect.
Affected Products
- Red Hat Enterprise Linux for x86_64 8 x86_64
- Red Hat Enterprise Linux for IBM z Systems 8 s390x
- Red Hat Enterprise Linux for Power, little endian 8 ppc64le
- Red Hat Enterprise Linux for ARM 64 8 aarch64
- Red Hat CodeReady Linux Builder for x86_64 8 x86_64
- Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
- Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
- Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x
Fixes
- RHEL-36185 - xmlsec1: Fix findings from static application security testing (SAST)
CVEs
(none)
References
(none)
Red Hat Enterprise Linux for x86_64 8
SRPM | |
---|---|
xmlsec1-1.2.25-8.el8_10.src.rpm | SHA-256: 226a5edecd22d2897a12f863385fbaffa887e8fb4ae9795c178eee74aef0b2d7 |
x86_64 | |
xmlsec1-1.2.25-8.el8_10.i686.rpm | SHA-256: 2ad31b14d7ca55a2834416ba8d9b8b7bf4be5e4b80272c3a75855b6ea42fc606 |
xmlsec1-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 73c09906003a8997a03ff0c02d2da3edd697a7c103b5ec35e3ca4f07aa0c0abf |
xmlsec1-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: 70501690e891c02fa005163777d9540204c6393470472c6ed1b9c57726b56d01 |
xmlsec1-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 6814660a2c870453e308fc5f2c3f71eeaf1ffd22054f323545bf38a1b72ff43d |
xmlsec1-debugsource-1.2.25-8.el8_10.i686.rpm | SHA-256: 258c7fa2666209172c1a34f4ae7f7b2b5f750672bc77f2597569b2c06e8e6f17 |
xmlsec1-debugsource-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 8931b31d80c001cc1c29f5235c4db2ede1770163abeecd610d89b2b682d8924d |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: c482204649e79f20f3e2f86b6e8b9c694ec0bd08380192943e44156ce3f5d3d2 |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 29ba908e35893fc4ec0174037b153fb315a461bea043869a9adf51682f3625c3 |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: 885059f81295426acdaf92a1d7a1d1a1860cc9bc345ccc5265529a624512241a |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 8b646869bf06666c846c085db33de2f652a4683eebdbac4f1f430fecf578db98 |
xmlsec1-nss-1.2.25-8.el8_10.i686.rpm | SHA-256: e11165e4d2271a9c2660e31b8703369f8579e39e1e6be8b1a30298f7246f3075 |
xmlsec1-nss-1.2.25-8.el8_10.x86_64.rpm | SHA-256: d0614bea84831619db47fd36fb8dfac2b8a436bc0654b0cb97b2cad3f359cc41 |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: 78eec5a46e7daf8f28846771bd732c45b0b06a6649cf6919f7bb622de1379f1a |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: ea8b1fedce837d0702c6fc67910f7fde833217b1c9ae9f979ae3ea5a1cf6f452 |
xmlsec1-openssl-1.2.25-8.el8_10.i686.rpm | SHA-256: e4db99967cf812f6fab99196a5135eb3a7b35f9d634b80d35c035f4eeb9484b9 |
xmlsec1-openssl-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 1c2aa0ce989db8e2c7a6bb7607a87392d11bb3995f4a3b89d4d510552e9ec30f |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: 1d00046470b2605b0d4ff8fe2651495979b184f774725f77ee3e70aec16cbe51 |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: a942c618252b64d942f0b5ac704e0d820f0442e1948b2cb7d5a147ae05e67c5b |
Red Hat Enterprise Linux for IBM z Systems 8
SRPM | |
---|---|
xmlsec1-1.2.25-8.el8_10.src.rpm | SHA-256: 226a5edecd22d2897a12f863385fbaffa887e8fb4ae9795c178eee74aef0b2d7 |
s390x | |
xmlsec1-1.2.25-8.el8_10.s390x.rpm | SHA-256: 50e555d04668e95e6fbbed31dcd33ac575f202dd7c95723d6bf2759b0f5431b2 |
xmlsec1-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 919ab62924a27cc1307d8a4b0adfd675c305fea1f96ee6f23cd5cba7c9e883fa |
xmlsec1-debugsource-1.2.25-8.el8_10.s390x.rpm | SHA-256: cfeabcada4c748820c872a5fed0ea8d0a4f6325812d192c6962ab9e05819912b |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 9801d5aa514757e6ec2767b5fb4dafd977300e9360a084d744c12e8156c9d905 |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 179f06a4041b5a5357d6b3ef9700088683ba3dd20570b22895ea49bfa8d6c809 |
xmlsec1-nss-1.2.25-8.el8_10.s390x.rpm | SHA-256: f33317b898377a93f7785cd9d5a7d6e7b528a24c262b7bf4690b36e68238f5f7 |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 76f582b05d348f2c6d31cb768ad3dc6297fed30e0f48ed89f129cb9c761e766d |
xmlsec1-openssl-1.2.25-8.el8_10.s390x.rpm | SHA-256: ae8e9f261334c6b7ce1c16e3ebb4947ee42091199dc59fa804a32c34cf982eb8 |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 96869fde8027809fe5f8c576012fbb4eba8d85aeeb8f9cfc8256f040b7655db2 |
Red Hat Enterprise Linux for Power, little endian 8
SRPM | |
---|---|
xmlsec1-1.2.25-8.el8_10.src.rpm | SHA-256: 226a5edecd22d2897a12f863385fbaffa887e8fb4ae9795c178eee74aef0b2d7 |
ppc64le | |
xmlsec1-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 07c8f41837aa454bd25d849d234d80fac9a2ba8473298aa05f04190ab5c9f14b |
xmlsec1-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: bda8668d3b7388a79ee47f2eab2d3e82dee1acb29f7941500bf99ac51afafa67 |
xmlsec1-debugsource-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 62cfc744bd9a4dfc3499d9d1d76fc0106adc298d7f6607beafe419a24edc490b |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 7511221655c1014b65da99e0fd2679d89d0e8af2d436ad90f7c186485247c60b |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 025fe7496da305f44fc8c1191fee5a883cd6b6613852dbc7141175b7b640b8fc |
xmlsec1-nss-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 732ebf58e30e335dd497c471033d7ff034735302f1d6bb1ce5b2a9e927e840fe |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 52c9c500afc83c3064662841b7907eec841d1d4ba7b55ac0fe65998d8e481c90 |
xmlsec1-openssl-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 38db1680884f2bb68f0e3bb7772157935ba9f175b2e4fad31c9f3f811e5f1da0 |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 777f413f47d00f5237b459cc0ca6515610547e18f10110ffe7970e08ba90034a |
Red Hat Enterprise Linux for ARM 64 8
SRPM | |
---|---|
xmlsec1-1.2.25-8.el8_10.src.rpm | SHA-256: 226a5edecd22d2897a12f863385fbaffa887e8fb4ae9795c178eee74aef0b2d7 |
aarch64 | |
xmlsec1-1.2.25-8.el8_10.aarch64.rpm | SHA-256: b9a2a28de56d08500072f96263c58cdb70254f3b87fe3a986381dc2eae9845e8 |
xmlsec1-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: da12058f39d419d9923dfb6a70d24018f92720aef6a85cd55b3a3a32916d9835 |
xmlsec1-debugsource-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 058b33e3048f5abd3c03b13c156d2175059f22cfd14769cc0a149590714ae55c |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 552d9a712355ca8bb3f1715f9e459e99971e920e7ab802a06d065cbe6db31911 |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: afad0667d03c447fb43ecb29ed969f82486f3e45d5b7b86fb00f8d878075cf66 |
xmlsec1-nss-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 2172611a81150823a6e35b1b7abdf4ed4567951c51b9333078a5138d0501d758 |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 0c91d4abfd120ba34b907a05df45434ae23b69c01582b406959d364b32a42765 |
xmlsec1-openssl-1.2.25-8.el8_10.aarch64.rpm | SHA-256: df74e60ebe66d2849f830f67316b428aeba1dc148f8d0eb953d96ff96bf0c17c |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 19b10f3265adc4e0109df5e2b485c6654a6e94fe1bbc6be66db787c6bed7b91e |
Red Hat CodeReady Linux Builder for x86_64 8
SRPM | |
---|---|
x86_64 | |
xmlsec1-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: 70501690e891c02fa005163777d9540204c6393470472c6ed1b9c57726b56d01 |
xmlsec1-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 6814660a2c870453e308fc5f2c3f71eeaf1ffd22054f323545bf38a1b72ff43d |
xmlsec1-debugsource-1.2.25-8.el8_10.i686.rpm | SHA-256: 258c7fa2666209172c1a34f4ae7f7b2b5f750672bc77f2597569b2c06e8e6f17 |
xmlsec1-debugsource-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 8931b31d80c001cc1c29f5235c4db2ede1770163abeecd610d89b2b682d8924d |
xmlsec1-devel-1.2.25-8.el8_10.i686.rpm | SHA-256: 2844aa6917ba0877ba444c114390ee962b9430d63ff6e60208255950358bc5da |
xmlsec1-devel-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 48e9ff405d5c8d6a96cb5115808c63aaf007fe7bb05fe9646b8d2ada690f7c7e |
xmlsec1-gcrypt-1.2.25-8.el8_10.i686.rpm | SHA-256: a7b015678bfd2f16a009a763cc833f8a1762f69e26b28cffe00710eb603275e2 |
xmlsec1-gcrypt-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 05cc43fc75843932d66c4a14d18d74b87597b701311c2ebbfab7f228a7b3e746 |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: c482204649e79f20f3e2f86b6e8b9c694ec0bd08380192943e44156ce3f5d3d2 |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 29ba908e35893fc4ec0174037b153fb315a461bea043869a9adf51682f3625c3 |
xmlsec1-gnutls-1.2.25-8.el8_10.i686.rpm | SHA-256: 3fbb610c687fe03a871dda79be18f10479ea42901cecb4d1d2b9ebb0fef22d69 |
xmlsec1-gnutls-1.2.25-8.el8_10.x86_64.rpm | SHA-256: c53a1144fcbfdc05085483916b6cde58911cf935afc4cca03c053bf5b2c1e679 |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: 885059f81295426acdaf92a1d7a1d1a1860cc9bc345ccc5265529a624512241a |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 8b646869bf06666c846c085db33de2f652a4683eebdbac4f1f430fecf578db98 |
xmlsec1-gnutls-devel-1.2.25-8.el8_10.i686.rpm | SHA-256: 8d5b529e07e97923f59b69b2437f4ee699415a26167e8715aa7114e6c019794b |
xmlsec1-gnutls-devel-1.2.25-8.el8_10.x86_64.rpm | SHA-256: db51c9dfb9f05d6ea33eba43afd8830568adea45b02849c9c83f8369cf466f60 |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: 78eec5a46e7daf8f28846771bd732c45b0b06a6649cf6919f7bb622de1379f1a |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: ea8b1fedce837d0702c6fc67910f7fde833217b1c9ae9f979ae3ea5a1cf6f452 |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.i686.rpm | SHA-256: 1d00046470b2605b0d4ff8fe2651495979b184f774725f77ee3e70aec16cbe51 |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.x86_64.rpm | SHA-256: a942c618252b64d942f0b5ac704e0d820f0442e1948b2cb7d5a147ae05e67c5b |
xmlsec1-openssl-devel-1.2.25-8.el8_10.i686.rpm | SHA-256: 589c22b9fa79dac8ef884853b5d6fe60ca2308157cd6aadaf1cc05d82b205095 |
xmlsec1-openssl-devel-1.2.25-8.el8_10.x86_64.rpm | SHA-256: 9478f092d2e8b1e6ad221dd5dc97bd72643178e8c28675015bf59f7509f5a660 |
Red Hat CodeReady Linux Builder for Power, little endian 8
SRPM | |
---|---|
ppc64le | |
xmlsec1-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: bda8668d3b7388a79ee47f2eab2d3e82dee1acb29f7941500bf99ac51afafa67 |
xmlsec1-debugsource-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 62cfc744bd9a4dfc3499d9d1d76fc0106adc298d7f6607beafe419a24edc490b |
xmlsec1-devel-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 24690e729c3f3e00f96129808e4709fc06ce5aa948d2f65086326d236baa2300 |
xmlsec1-gcrypt-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 0e726fcc1d3654948b57bbd8b18d4dc723c84db66aa0f7de7ce1b6c5b408f723 |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 7511221655c1014b65da99e0fd2679d89d0e8af2d436ad90f7c186485247c60b |
xmlsec1-gnutls-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 73c2129f72cfb72a569f67b44392b5ca036ef94f1fd801436b7dba0d7cd5760c |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 025fe7496da305f44fc8c1191fee5a883cd6b6613852dbc7141175b7b640b8fc |
xmlsec1-gnutls-devel-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: fca9240a8bb9f1cf8be75551c4b03f58c851a45921eab2adb3b513159ee6dab4 |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 52c9c500afc83c3064662841b7907eec841d1d4ba7b55ac0fe65998d8e481c90 |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: 777f413f47d00f5237b459cc0ca6515610547e18f10110ffe7970e08ba90034a |
xmlsec1-openssl-devel-1.2.25-8.el8_10.ppc64le.rpm | SHA-256: f278225528ac6a236986314a9c06e9658370a3c765b49f3d0458613b8c20996a |
Red Hat CodeReady Linux Builder for ARM 64 8
SRPM | |
---|---|
aarch64 | |
xmlsec1-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: da12058f39d419d9923dfb6a70d24018f92720aef6a85cd55b3a3a32916d9835 |
xmlsec1-debugsource-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 058b33e3048f5abd3c03b13c156d2175059f22cfd14769cc0a149590714ae55c |
xmlsec1-devel-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 879f7f5c2ae28c1db252ce8fc434125e311b56112e944d5aeccee6b20a82f544 |
xmlsec1-gcrypt-1.2.25-8.el8_10.aarch64.rpm | SHA-256: e78e99d4a1f7c10d135b9d6c09097963c7746e567ac7e39716c61dda5e34864c |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 552d9a712355ca8bb3f1715f9e459e99971e920e7ab802a06d065cbe6db31911 |
xmlsec1-gnutls-1.2.25-8.el8_10.aarch64.rpm | SHA-256: e011320a5a076aef84664d5cd25c98bff4243d678da88e3bbb02ba877b65164f |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: afad0667d03c447fb43ecb29ed969f82486f3e45d5b7b86fb00f8d878075cf66 |
xmlsec1-gnutls-devel-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 8df0fa3f44d9b36a2fe2c9c904d3196f87215dcd258c7025bcf2d27b74b432d2 |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 0c91d4abfd120ba34b907a05df45434ae23b69c01582b406959d364b32a42765 |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 19b10f3265adc4e0109df5e2b485c6654a6e94fe1bbc6be66db787c6bed7b91e |
xmlsec1-openssl-devel-1.2.25-8.el8_10.aarch64.rpm | SHA-256: 7d6f66a321b5eb37b6f3178f5538430db78579a821408f30e5a7fec0365d24b6 |
Red Hat CodeReady Linux Builder for IBM z Systems 8
SRPM | |
---|---|
s390x | |
xmlsec1-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 919ab62924a27cc1307d8a4b0adfd675c305fea1f96ee6f23cd5cba7c9e883fa |
xmlsec1-debugsource-1.2.25-8.el8_10.s390x.rpm | SHA-256: cfeabcada4c748820c872a5fed0ea8d0a4f6325812d192c6962ab9e05819912b |
xmlsec1-devel-1.2.25-8.el8_10.s390x.rpm | SHA-256: 702b37952a86460b1de5b0da18db97c014d97dddd02e7250f1e0321b21eaad77 |
xmlsec1-gcrypt-1.2.25-8.el8_10.s390x.rpm | SHA-256: cdf2fea353edd98d4d4460dc6fa16d0d8fb92a43ad8c5012a969e52059545657 |
xmlsec1-gcrypt-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 9801d5aa514757e6ec2767b5fb4dafd977300e9360a084d744c12e8156c9d905 |
xmlsec1-gnutls-1.2.25-8.el8_10.s390x.rpm | SHA-256: 37d7b02a4e33dc7b87a19acbb87f0f51479540e970a030da372641ea4620d6a3 |
xmlsec1-gnutls-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 179f06a4041b5a5357d6b3ef9700088683ba3dd20570b22895ea49bfa8d6c809 |
xmlsec1-gnutls-devel-1.2.25-8.el8_10.s390x.rpm | SHA-256: af572877ebf224a65a144321b014a1a584ca36faf04174193f34bfe751fc17e5 |
xmlsec1-nss-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 76f582b05d348f2c6d31cb768ad3dc6297fed30e0f48ed89f129cb9c761e766d |
xmlsec1-openssl-debuginfo-1.2.25-8.el8_10.s390x.rpm | SHA-256: 96869fde8027809fe5f8c576012fbb4eba8d85aeeb8f9cfc8256f040b7655db2 |
xmlsec1-openssl-devel-1.2.25-8.el8_10.s390x.rpm | SHA-256: f3ae19168258482c6c8f544fe08340be8ca17f1b3590033fd630486c4c19e541 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.