You are here
Home > Preporuke > Sigurnosni propusti programske biblioteke libxml2

Sigurnosni propusti programske biblioteke libxml2

  • Detalji os-a: LUB
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2812-1
November 16, 2015

libxml2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 15.10
– Ubuntu 15.04
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in libxml2.

Software Description:
– libxml2: GNOME XML library

Details:

Florian Weimer discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause resource consumption,
resulting in a denial of service. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-1819)

Michal Zalewski discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause libxml2 to crash,
resulting in a denial of service. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-7941)

Kostya Serebryany discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-7942)

Gustavo Grieco discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause libxml2 to crash,
resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2015-8035)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
libxml2 2.9.2+zdfsg1-4ubuntu0.1

Ubuntu 15.04:
libxml2 2.9.2+dfsg1-3ubuntu0.1

Ubuntu 14.04 LTS:
libxml2 2.9.1+dfsg1-3ubuntu4.5

Ubuntu 12.04 LTS:
libxml2 2.7.8.dfsg-5.1ubuntu4.12

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2812-1
CVE-2015-1819, CVE-2015-7941, CVE-2015-7942, CVE-2015-8035

Package Information:
https://launchpad.net/ubuntu/+source/libxml2/2.9.2+zdfsg1-4ubuntu0.1
https://launchpad.net/ubuntu/+source/libxml2/2.9.2+dfsg1-3ubuntu0.1
https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5
https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.12

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJWSie3AAoJEGVp2FWnRL6T5KoP/jdnAQVuRvSE2nn06TrwdNy2
8u2Azjg35e6tNIvrzGP/PXfXROXCuOEfi+NHr8hVi0h+nlc18KyHlCiw6PYjcOyC
uWIhJ7cNQkuXCdfHqVJoD0DjEXrLq8I5/dcMnYR8YHH+4QuexGnnVn2x77jRifak
FKHWwmQ//Fzb4B3s2DmnhjdR7mZEhdeNRLOiMfQHdivATgdKKE68tpx0vCU9cuHn
V+ldPlJk8ZiBS92GDi4yhrH4My6TR9H5HVU0FzDGv6KFNulY/Ip9GaVTbHrRJm4Q
OjopGt8NNy8ECRz7MmiDwlyTtLPmzhG3WCX8x93iQ4kb1FBqBqcCce55MZPqCVAx
QcmC7A2BuU63oCadyGgpJN/i6q38cfbFaqonOY8l8GLbAJ9ml9BBFws01LvAjpUC
8R6IWzA6aLBu5Nt1cBMO2DbdfRJmB0KfjNJwciopy5T4FAhnyYhCejpMHxYcbVlX
dCtRUm6psKgKgWivwLiYsb5UnSNmzXN1QnUppzLWFM6y6za7zYdrIatCxQQn0zvC
SVn5PfpczcN2vbTPZE5NjyItHWpVK0H2ozmKwPkK86tS7YGR/sL0ycTkoHg1Nfud
rR6dMNpRnIMmF93gL1Babvwo8v299iun8t7KwyjX8DTQcVa1Kj/nmUzRUC+QjeBO
vqM1oDvgRv1te10OU0HQ
=l9Fe
—–END PGP SIGNATURE—–

AutorTomislav Protega
Cert idNCERT-REF-2015-11-0013-ADV
CveCVE-2015-1819 CVE-2015-7941 CVE-2015-7942 CVE-2015-8035
ID izvornikaUSN-2812-1
Proizvodlibxml2
Izvorhttp://www.ubuntu.com
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa krb5

Otkrivene su ranjivosti u programskom paketu krb5 za openSUSE Leap 42.1. Ranjivosti su posljedica neispravnog upravljanja paketima SPNEGO i IAKERB...

Close