Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2015-0749

Опубликовано: 30 мар. 2015
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2015-0749: libxml2 security update (MODERATE)

[2.9.1-5.0.1.el7_1.2]

  • Update doc/redhat.gif in tarball
  • Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.9.1-5.2]

  • Fix missing entities after CVE-2014-3660 fix
  • CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195649)
  • Fix regressions introduced by CVE-2014-0191 patch

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

libxml2

2.9.1-5.0.1.el7_1.2

libxml2-devel

2.9.1-5.0.1.el7_1.2

libxml2-python

2.9.1-5.0.1.el7_1.2

libxml2-static

2.9.1-5.0.1.el7_1.2

Связанные CVE

Связанные уязвимости

ubuntu
больше 10 лет назад

The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.

redhat
больше 11 лет назад

The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.

nvd
больше 10 лет назад

The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.

debian
больше 10 лет назад

The xmlParserHandlePEReference function in parser.c in libxml2 before ...

suse-cvrf
почти 9 лет назад

Recommended update for libxml2