Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

CentOS 6: CENTOS-2011-5678 Urgent OpenSSL Vulnerability Fix

fedora
Calendar Grey August 15, 2009
Dist Fedora Esm H88
Fedora 11 has rolled out an update addressing security vulnerabilities in libxml. The patch includes vital fixes to counter serious threats and improves overall system integrity
This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary ...

Summary

This library allows old Gnome-1 applications to manipulate XML files.

Update Information:

This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities)

Change Log

* Wed Aug 12 2009 Paul Howarth 1:1.8.17-24 - renumber existing patches to free up low-numbered patches for EL-3 patches - add patch for CAN-2004-0110 and CAN-2004-0989 (#139090) - add patch for CVE-2009-2414 and CVE-2009-2416 (#515195, #515205) * Sat Jul 25 2009 Fedora Release Engineering 1:1.8.17-23 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Mon Apr 20 2009 Paul Howarth 1:1.8.17-22 - rebuild for %{_isa} provides/requires

References


[ 1 ] Bug #430644 - CVE-2004-0110 libxml2 long URL causes SEGV https://bugzilla.redhat.com/show_bug.cgi?id=430644 [ 2 ] Bug #430645 - CVE-2004-0989 libxml2 various overflows https://bugzilla.redhat.com/show_bug.cgi?id=430645 [ 3 ] Bug #515195 - CVE-2009-2414 libxml, libxml2: Stack overflow by parsing root XML element DTD definition https://bugzilla.redhat.com/show_bug.cgi?id=515195 [ 4 ] Bug #515205 - CVE-2009-2416 libxml, libxml2: Pointer use-after-free flaws by parsing Notation and Enumeration attribute types https://bugzilla.redhat.com/show_bug.cgi?id=515205

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update libxml' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libxml
Product: Fedora 11
Version: 1.8.17
Release: 24.fc11
Summary: Old XML library for Gnome-1 application compatibility

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here