Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Debian: DSA-3057-2 Critical: libxml2 Denial Of Service Patch

debian
Calendar Grey April 7, 2015
Debian Logo
Ubuntu libxml2 upgrade fixes bugs introduced by prior fix, resolving security vulnerability related to denial of service.
The update for libxml2 issued as DSA-3057-1 caused regressions due to an incomplete patch to address CVE-2014-3660

Summary

Sogeti found a denial of service flaw in libxml2, a library providing
support to read, modify and write XML and HTML files. A remote attacker
could provide a specially crafted XML file that, when processed by an
application using libxml2, would lead to excessive CPU consumption
(denial of service) based on excessive entity substitutions, even if
entity substitution was disabled, which is the parser default behavior.
(CVE-2014-3660)

For the stable distribution (wheezy), this problem has been fixed in
version 2.8.0+dfsg1-7+wheezy4.

We recommend that you upgrade your libxml2 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here