ArchLinux: 201410-12: libxml2: Denial of service
Summary
Daniel Berrange discovered that libxml2 incorrectly performs entity substitution in the doctype prolog, even if the application using libxml2 disabled any entity substitution. A remote attacker could provide a specially crafted XML file that, when processed, leads to the exhaustion of CPU and memory resources or file descriptors.
Resolution
Upgrade to 2.9.2-1.
# pacman -Syu "libxml2>=2.9.2-1"
The problems have been fixed upstream [0][1] in version 2.9.2.
References
[0] https://gitlab.gnome.org/users/sign_in [1] https://gitlab.gnome.org/users/sign_in https://access.redhat.com/security/cve/CVE-2014-0191 https://access.redhat.com/security/cve/CVE-2014-3660 https://bugs.archlinux.org/task/40790 https://www.openwall.com/lists/oss-security/2014/05/06/4
Workaround
None.