You are here
Home > Preporuke > Sigurnosni nedostaci programske biblioteke libxml2

Sigurnosni nedostaci programske biblioteke libxml2

==========================================================================
Ubuntu Security Notice USN-3424-2
October 10, 2017

libxml2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in libxml2.

Software Description:
– libxml2: GNOME XML library

Details:

USN-3424-1 fixed several vulnerabilities in libxml2. This update
provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that a type confusion error existed in libxml2. An
 attacker could use this to specially construct XML data that
 could cause a denial of service or possibly execute arbitrary
 code. (CVE-2017-0663)

 It was discovered that libxml2 did not properly validate parsed entity
 references. An attacker could use this to specially construct XML
 data that could expose sensitive information. (CVE-2017-7375)

 It was discovered that a buffer overflow existed in libxml2 when
 handling HTTP redirects. An attacker could use this to specially
 construct XML data that could cause a denial of service or possibly
 execute arbitrary code. (CVE-2017-7376)

 Marcel Böhme and Van-Thuan Pham discovered a buffer overflow in
 libxml2 when handling elements. An attacker could use this to
 specially construct XML data that could cause a denial of service or
 possibly execute arbitrary code. (CVE-2017-9047)

 Marcel Böhme and Van-Thuan Pham discovered a buffer overread
 in libxml2 when handling elements. An attacker could use this
 to specially construct XML data that could cause a denial of
 service. (CVE-2017-9048)

 Marcel Böhme and Van-Thuan Pham discovered multiple buffer overreads
 in libxml2 when handling parameter-entity references. An attacker
 could use these to specially construct XML data that could cause a
 denial of service. (CVE-2017-9049, CVE-2017-9050)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  libxml2                         2.7.8.dfsg-5.1ubuntu4.18

In general, a standard system update will make all the necessary
changes.

References:
  https://www.ubuntu.com/usn/usn-3424-2
  https://www.ubuntu.com/usn/usn-3424-1
  CVE-2017-0663, CVE-2017-7375, CVE-2017-7376, CVE-2017-9047,
  CVE-2017-9048, CVE-2017-9049, CVE-2017-9050
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAABCAAGBQJZ3S0KAAoJEEW851uECx9pSSwP/RVIIqBpcFgS0dFlF2VYm+dw
XlHTwByj48ob3y03oyoyiBp7Jp1bH7r935wok9CkGuo8UvY0+6n8KySqkJEeK5Ki
7kiRrZKa+QVYCaqXIPahR5Jrpo+tG9mmjZ3b7CABRF1/e9RPPK+2Fa6hYe4jwMyV
Q4HIrgSy5yYQTeSmWloKmu64dbOvOtPMqDhDIBwmT8hK7v8T08K3BPYFAf4Tfrmg
EaJPY2bLR7Q6bY8sZ/nGlL3PXYT+sL3LhH1su28egXw0d+WJs26qeDkESzISXRRt
bW2Vdb4AQV9vrU/BpJKjiDxcs9lKzek8xZxsSqSs2UTsfBkDvDwLvD4erbDNMG4j
Qw6JCqhQvCH2uWIeiVcxO1i/FPCPr5P5Jde5qCLzg5hBOyEzl6dEYdSjcffwe32H
8FjFHLV8d1ny0Tg1hsVFJxmv5rHLZi84XNZTrmiQX1Z7/G3Nz8o3Qd8p/hydhYlB
P6kxOKDusUOTo0oeRuhcSEjpezsKWitApTLyMc2xC76zIq/Spi1qMcVGXqfSMu4E
6uZs3hqK9B2aYqKy3TKshPpV6BZPk5oHtYKcLSEshtIFhGtBU5Cf4ZTQObHQf7+A
vzB8wfCPNWPD6wwsjPSTjGgKxup7nbwlB5heHlXWYkZ0pU3AWL4k0GNWToiSn2zu
efArzFSgNRz+OUHVulWx
=X0Xo
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa ImageMagick

Otkriven je sigurnosni nedostatak u programskom paketu ImageMagick za operacijski sustav Fedora. Otkriveni nedostatak potencijalnim napadačima omogućuje izvođenje napada uskraćivanja...

Close