Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:0164-1

Опубликовано: 16 янв. 2017
Источник: suse-cvrf

Описание

Security update for libxml2

This update for libxml2 fixes the following issues:

  • CVE-2016-9318: libxml2 did not offer a flag directly indicating that the current document may be read but other files may not be opened, which made it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document (bsc#1010675).
  • Prevent NULL dereference in xpointer.c and xmlDumpElementContent, and infinite recursion in xmlParseConditionalSections when in recovery mode(bnc#1014873)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
libxml2-2.7.6-0.64.1
libxml2-32bit-2.7.6-0.64.1
libxml2-doc-2.7.6-0.64.1
libxml2-python-2.7.6-0.64.4
libxml2-x86-2.7.6-0.64.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libxml2-2.7.6-0.64.1
libxml2-32bit-2.7.6-0.64.1
libxml2-doc-2.7.6-0.64.1
libxml2-python-2.7.6-0.64.4
libxml2-x86-2.7.6-0.64.1
SUSE Linux Enterprise Software Development Kit 11 SP4
libxml2-devel-2.7.6-0.64.1
libxml2-devel-32bit-2.7.6-0.64.1

Описание

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libxml2-2.7.6-0.64.1
SUSE Linux Enterprise Server 11 SP4:libxml2-32bit-2.7.6-0.64.1
SUSE Linux Enterprise Server 11 SP4:libxml2-doc-2.7.6-0.64.1
SUSE Linux Enterprise Server 11 SP4:libxml2-python-2.7.6-0.64.4

Ссылки