SuSE: 2013:1627-1: important: libxml2
Summary
libxml2 has been updated to fix the following security
issue:
* CVE-2013-0338: libxml2 allowed context-dependent
attackers to cause a denial of service (CPU and memory
consumption) via an XML file containing an entity
declaration with long replacement text and many references
to this entity, aka "internal entity expansion" with linear
complexity.
Security Issue references:
* CVE-2013-0338
References
#829077
Cross- CVE-2011-3102 CVE-2011-3919 CVE-2012-0841
CVE-2012-2807 CVE-2012-5134 CVE-2013-0338
CVE-2013-0339 CVE-2013-2877
Affected Products:
SUSE Linux Enterprise Server 10 SP4 LTSS
https://www.suse.com/security/cve/CVE-2011-3102.html
https://www.suse.com/security/cve/CVE-2011-3919.html
https://www.suse.com/security/cve/CVE-2012-0841.html
https://www.suse.com/security/cve/CVE-2012-2807.html
https://www.suse.com/security/cve/CVE-2012-5134.html
https://www.suse.com/security/cve/CVE-2013-0338.html
https://www.suse.com/security/cve/CVE-2013-0339.html
https://www.suse.com/security/cve/CVE-2013-2877.html
https://bugzilla.novell.com/829077
https://login.microfocus.com/nidp/app/login