Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian: DSA-2395-1 Severe: OpenSSL Denial of Service Vulnerability

debian
Calendar Grey January 26, 2012
Debian Logo
Crucial patch released for libxml2 tackling various security flaws. Users are advised to update their packages without delay.
Many security problems had been fixed in libxml2, a popular library to handle XML data files

Summary

CVE-2011-3919:
Jüri Aedla discovered a heap-based buffer overflow that allows remote attackersto cause a denial of service or possibly have unspecified other impact via
unknown vectors.

CVE-2011-0216:
An Off-by-one error have been discoveried that allows remote attackers to
execute arbitrary code or cause a denial of service.

CVE-2011-2821:
A memory corruption (double free) bug has been identified in libxml2's XPath
engine. Through it, it is possible to an attacker allows cause a denial of
service or possibly have unspecified other impact. This vulnerability does not
affect the oldstable distribution (lenny).

CVE-2011-2834:
Yang Dingning discovered a double free vulnerability related to XPath handling.

CVE-2011-3905:
An out-of-bounds read vulnerability had been discovered, which allows remote
attackers to cause a denial of service.

For the oldstable distribution (lenny), this problem has been fixed in
version 2.6.32.dfsg-5+lenny5.

For the stable distribution (squeeze), this problem has been fix...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: libxml2
CVE ID: CVE-2011-0216 CVE-2011-2821 CVE-2011-2834 CVE-2011-3905

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here