Описание
Security update for libxml2
This update for libxml2 fixes the following issues:
Security issue fixed:
- CVE-2018-14404: Prevent NULL pointer dereference in the xmlXPathCompOpEval() function when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case leading to a denial of service attack (bsc#1102046)
Other Issue fixed:
- Fixed a bug related to the fix for CVE-2016-9318 which allowed xsltproc to access the internet even when --nonet was given and also was making docbook-xsl-stylesheets to have incomplete xml catalog file (bsc#1010675, bsc#1126613 and bsc#1110146).
Список пакетов
SUSE Linux Enterprise Point of Sale 11 SP3
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
Ссылки
- Link for SUSE-SU-2019:13985-1
- E-Mail link for SUSE-SU-2019:13985-1
- SUSE Security Ratings
- SUSE Bug 1010675
- SUSE Bug 1102046
- SUSE Bug 1110146
- SUSE Bug 1126613
- SUSE CVE CVE-2016-9318 page
- SUSE CVE CVE-2018-14404 page
Описание
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
Затронутые продукты
Ссылки
- CVE-2016-9318
- SUSE Bug 1010675
- SUSE Bug 1014873
- SUSE Bug 1019074
- SUSE Bug 1118959
- SUSE Bug 1123919
- SUSE Bug 1126613
- SUSE Bug 1148896
Описание
A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.
Затронутые продукты
Ссылки
- CVE-2018-14404
- SUSE Bug 1102046
- SUSE Bug 1148896