Описание
Security update for libxml2
This update for libxml2 fixes the following issues:
Security issues fixed:
- CVE-2017-7376: Increase buffer space for port in HTTP redirect support (bsc#1044887)
- CVE-2017-7375: Prevent unwanted external entity reference (bsc#1044894)
This update was imported from the SUSE:SLE-12-SP2:Update update project.
Список пакетов
openSUSE Leap 42.2
Ссылки
- E-Mail link for openSUSE-SU-2017:1810-1
- SUSE Security Ratings
Описание
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).
Затронутые продукты
Ссылки
- CVE-2017-7375
- SUSE Bug 1044894
- SUSE Bug 1049467
- SUSE Bug 1123919
Описание
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
Затронутые продукты
Ссылки
- CVE-2017-7376
- SUSE Bug 1044887
- SUSE Bug 1049467
- SUSE Bug 1123919