From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-200812-06.xml | 96 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 96 insertions(+) create mode 100644 metadata/glsa/glsa-200812-06.xml (limited to 'metadata/glsa/glsa-200812-06.xml') diff --git a/metadata/glsa/glsa-200812-06.xml b/metadata/glsa/glsa-200812-06.xml new file mode 100644 index 000000000000..da036f1d34c7 --- /dev/null +++ b/metadata/glsa/glsa-200812-06.xml @@ -0,0 +1,96 @@ + + + + libxml2: Multiple vulnerabilities + + Multiple vulnerabilities in libxml2 might lead to execution of arbitrary + code or Denial of Service. + + libxml2 + 2008-12-02 + 2008-12-02: 01 + 234099 + 237806 + 239346 + 245960 + remote + + + 2.7.2-r1 + 2.7.2-r1 + + + +

+ libxml2 is the XML (eXtended Markup Language) C parser and toolkit + initially developed for the Gnome project. +

+
+ +

+ Multiple vulnerabilities were reported in libxml2: +

+
    +
  • + Andreas Solberg reported that libxml2 does not properly detect + recursion during entity expansion in an attribute value + (CVE-2008-3281). +
  • +
  • + A heap-based buffer overflow has been reported in the + xmlParseAttValueComplex() function in parser.c (CVE-2008-3529). +
  • +
  • + Christian Weiske reported that predefined entity definitions in + entities are not properly handled (CVE-2008-4409). +
  • +
  • + Drew Yao of Apple Product Security reported an integer overflow in the + xmlBufferResize() function that can lead to an infinite loop + (CVE-2008-4225). +
  • +
  • + Drew Yao of Apple Product Security reported an integer overflow in the + xmlSAX2Characters() function leading to a memory corruption + (CVE-2008-4226). +
  • +
+
+ +

+ A remote attacker could entice a user or automated system to open a + specially crafted XML document with an application using libxml2, + possibly resulting in the exeution of arbitrary code or a high CPU and + memory consumption. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All libxml2 users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/libxml2-2.7.2-r1" +
+ + CVE-2008-3281 + CVE-2008-3529 + CVE-2008-4409 + CVE-2008-4225 + CVE-2008-4226 + + + keytoaster + + + rbu + + + rbu + +
-- cgit v1.2.3