Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1152-1

Опубликовано: 31 мар. 2026
Источник: suse-cvrf

Описание

Security update for perl-XML-Parser

This update for perl-XML-Parser fixes the following issues:

  • CVE-2006-10002: heap buffer overflow in parse_stream when processing UTF-8 input streams (bsc#1259901).
  • CVE-2006-10003: off-by-one heap buffer overflow in st_serial_stack (bsc#1259902).

Список пакетов

Image SLES12-SP5-Azure-BYOS
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-HPC-BYOS
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-HPC-On-Demand
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-SAP-BYOS
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-SAP-On-Demand
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-Standard-On-Demand
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-EC2-BYOS
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-EC2-ECS-On-Demand
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-EC2-On-Demand
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-EC2-SAP-BYOS
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-EC2-SAP-On-Demand
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-GCE-BYOS
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-GCE-On-Demand
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-GCE-SAP-BYOS
perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-GCE-SAP-On-Demand
perl-XML-Parser-2.41-23.3.1
SUSE Linux Enterprise Server 12 SP5-LTSS
perl-XML-Parser-2.41-23.3.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
perl-XML-Parser-2.41-23.3.1

Описание

XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes. A :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input buffer because Perl's read() returns decoded characters while SvPV() gives back multi-byte UTF-8 bytes that can exceed the pre-allocated buffer size. This can cause heap corruption (double free or corruption) and crashes.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-HPC-BYOS:perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-HPC-On-Demand:perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-SAP-BYOS:perl-XML-Parser-2.41-23.3.1

Ссылки

Описание

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-HPC-BYOS:perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-HPC-On-Demand:perl-XML-Parser-2.41-23.3.1
Image SLES12-SP5-Azure-SAP-BYOS:perl-XML-Parser-2.41-23.3.1

Ссылки