Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:1896-1

Опубликовано: 18 июл. 2019
Источник: suse-cvrf

Описание

Security update for libxml2

This update for libxml2 fixes the following issues:

Issue fixed:

  • Fixed a bug related to the fix for CVE-2016-9318 which allowed xsltproc to access the internet even when --nonet was given and also was making docbook-xsl-stylesheets to have incomplete xml catalog file (bsc#1010675, bsc#1126613 and bsc#1110146).

Список пакетов

Container caasp/v4/nginx-ingress-controller:beta1
libxml2-2-2.9.4-46.20.1
Container suse/ltss/sle12.5/sles12sp5:latest
libxml2-2-2.9.4-46.20.1
Container suse/sles12sp3:latest
libxml2-2-2.9.4-46.20.1
Container suse/sles12sp4:latest
libxml2-2-2.9.4-46.20.1
Container suse/sles12sp5:latest
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-Azure-BYOS
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-Azure-Basic-On-Demand
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-Azure-HPC-BYOS
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-Azure-HPC-On-Demand
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-Azure-SAP-BYOS
libxml2-2-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
Image SLES12-SP5-Azure-SAP-On-Demand
libxml2-2-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
Image SLES12-SP5-Azure-Standard-On-Demand
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-EC2-BYOS
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-EC2-ECS-On-Demand
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-EC2-On-Demand
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-EC2-SAP-BYOS
libxml2-2-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
Image SLES12-SP5-EC2-SAP-On-Demand
libxml2-2-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
Image SLES12-SP5-GCE-BYOS
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-GCE-On-Demand
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-GCE-SAP-BYOS
libxml2-2-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
Image SLES12-SP5-GCE-SAP-On-Demand
libxml2-2-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
Image SLES12-SP5-OCI-BYOS-BYOS
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
libxml2-2-2.9.4-46.20.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
libxml2-2-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
libxml2-2-2.9.4-46.20.1
libxml2-2-32bit-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
SUSE Linux Enterprise Desktop 12 SP4
libxml2-2-2.9.4-46.20.1
libxml2-2-32bit-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
python-libxml2-2.9.4-46.20.1
SUSE Linux Enterprise Server 12 SP4
libxml2-2-2.9.4-46.20.1
libxml2-2-32bit-2.9.4-46.20.1
libxml2-doc-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
python-libxml2-2.9.4-46.20.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libxml2-2-2.9.4-46.20.1
libxml2-2-32bit-2.9.4-46.20.1
libxml2-doc-2.9.4-46.20.1
libxml2-tools-2.9.4-46.20.1
python-libxml2-2.9.4-46.20.1
SUSE Linux Enterprise Software Development Kit 12 SP4
libxml2-devel-2.9.4-46.20.1

Описание

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.


Затронутые продукты
Container caasp/v4/nginx-ingress-controller:beta1:libxml2-2-2.9.4-46.20.1
Container suse/ltss/sle12.5/sles12sp5:latest:libxml2-2-2.9.4-46.20.1
Container suse/sles12sp3:latest:libxml2-2-2.9.4-46.20.1
Container suse/sles12sp4:latest:libxml2-2-2.9.4-46.20.1

Ссылки
Уязвимость SUSE-SU-2019:1896-1