The vendor explicitly identifies these products as affected by this CVE.
- libxml2 as a component of Red Hat Enterprise Linux 6
- libxml2-devel as a component of Red Hat Enterprise Linux 6
- libxml2-python as a component of Red Hat Enterprise Linux 6
- libxml2-static as a component of Red Hat Enterprise Linux 6
- libxml2.src as a component of Red Hat Enterprise Linux 6
- libxml2 as a component of Red Hat Enterprise Linux 7
- libxml2-devel as a component of Red Hat Enterprise Linux 7
- libxml2-python as a component of Red Hat Enterprise Linux 7
- libxml2-static as a component of Red Hat Enterprise Linux 7
- libxml2.src as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in the xmllint program distributed by the libxml2 package. A buffer over-read in the xmlHTMLPrintFileContext function in the xmllint.c file may be triggered when a crafted file is processed with the xmllint program using the `--htmlout` command line option, causing an application crash and resulting in a denial of service.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
