Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Fedora 23 Security Advisory: libxml2 Update Critical Denial of Service

fedora
Calendar Grey November 26, 2015
Scroller Fedora
Important revision for Fedora 23's libxml2 addresses critical security flaws and various issues, essential for XML developers.
Very large set of security issues for libxml2 and a bunch of bug fixes too#CVE-2015-8242 #CVE-2015-7500 #CVE-2015-7499 #CVE-2015-5312 #CVE-2015-7498 #CVE-2015-7497 #CVE-2015-1819 #...

Summary

This library allows to manipulate XML files. It includes support

to read, modify and write XML and HTML files. There is DTDs support

this includes parsing and validation even with complex DtDs, either

at parse time or later once the document has been modified. The output

can be a simple SAX stream or and in-memory DOM like representations.

In this case one can use the built-in XPath and XPointer implementation

to select sub nodes or ranges. A flexible Input/Output mechanism is

available, with existing HTTP and FTP modules and combined to an

URI library.

Update Information:

Very large set of security issues for libxml2 and a bunch of bug fixes too#CVE-2015-8242 #CVE-2015-7500 #CVE-2015-7499 #CVE-2015-5312 #CVE-2015-7498 #CVE-2015-7497 #CVE-2015-1819 #CVE-2015-7941 #CVE-2015-7942 #CVE-2015-8035

Change Log

References


[ 1 ] Bug #1211278 - CVE-2015-1819 libxml2: denial of service processing a crafted XML document https://bugzilla.redhat.com/show_bug.cgi?id=1211278

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update libxml2' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libxml2
Product: Fedora 23
Version: 2.9.3
Release: 1.fc23
Summary: Library providing XML and HTML support

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.