Описание
Security update for perl-XML-LibXML
perl-XML-LibXML was updated to fix the expand_entities option to be preserved in all cases. (CVE-2015-3451).
Список пакетов
SUSE Linux Enterprise Desktop 12
perl-XML-LibXML-2.0019-5.3
SUSE Linux Enterprise Server 12
perl-XML-LibXML-2.0019-5.3
SUSE Linux Enterprise Server for SAP Applications 12
perl-XML-LibXML-2.0019-5.3
Ссылки
- Link for SUSE-SU-2015:1439-1
- E-Mail link for SUSE-SU-2015:1439-1
- SUSE Security Ratings
- SUSE Bug 929237
- SUSE CVE CVE-2015-3451 page
Описание
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
Затронутые продукты
SUSE Linux Enterprise Desktop 12:perl-XML-LibXML-2.0019-5.3
SUSE Linux Enterprise Server 12:perl-XML-LibXML-2.0019-5.3
SUSE Linux Enterprise Server for SAP Applications 12:perl-XML-LibXML-2.0019-5.3
Ссылки
- CVE-2015-3451
- SUSE Bug 929237