SuSE: 2013:1625-1: important: libxml2
Summary
This is a LTSS rollup update for the libxml2 library that fixes various security issues. * CVE-2013-2877: parser.c in libxml2 allowed remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state. * CVE-2013-0338: libxml2 allowed context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity. * CVE-2012-5134: Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 allowed remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document. * CVE-2012-2807: Multiple integer overflows in libxml2 on 64-bit Linux platforms allowe...
Read the Full AdvisoryReferences
#739894 #748561 #764538 #769184 #793334 #805233
#829077
Cross- CVE-2011-3102 CVE-2011-3919 CVE-2012-0841
CVE-2012-2807 CVE-2012-5134 CVE-2013-0338
CVE-2013-0339 CVE-2013-2877
Affected Products:
SUSE Linux Enterprise Server 10 SP3 LTSS
https://www.suse.com/security/cve/CVE-2011-3102.html
https://www.suse.com/security/cve/CVE-2011-3919.html
https://www.suse.com/security/cve/CVE-2012-0841.html
https://www.suse.com/security/cve/CVE-2012-2807.html
https://www.suse.com/security/cve/CVE-2012-5134.html
https://www.suse.com/security/cve/CVE-2013-0338.html
https://www.suse.com/security/cve/CVE-2013-0339.html
https://www.suse.com/security/cve/CVE-2013-2877.html
https://bugzilla.novell.com/739894
https://bugzilla.novell.com/748561
https://bugzilla.novell.com/764538
https://bugzilla.novell.com/769184
https://bugzilla.novell.com/793334
https://bugzilla.novell.com/805233
https://bug...
Read the Full Advisory