Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Gentoo: 202310-01 Urgent: OpenSSL Security Vulnerability Notification

gentoo
Calendar Grey March 6, 2004
Scroller Gentoo
Mitigating Libxml2 buffer overflow threats in Gentoo to avert execution risk of malicious code.
A buffer overflow has been discovered in libxml2 versions prior to 2.6.6 which may be exploited by an attacker allowing the execution of arbitrary code

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200403-01
~                                            https://security.gentoo.org/

~ Severity: Normal ~ Title: Libxml2 URI Parsing Buffer Overflow Vulnerabilities ~ Date: March 06, 2004 ~ Bugs: #42735 ~ ID: 200403-01

Synopsis ======= A buffer overflow has been discovered in libxml2 versions prior to 2.6.6 which may be exploited by an attacker allowing the execution of arbitrary code.
========== Yuuichi Teranishi discovered a flaw in libxml2 versions prior to 2.6.6. When the libxml2 library fetches a remote resource via FTP or HTTP, libxml2 uses parsing routines that can overflow a buffer caused by improper bounds checking if they are passed a URL longer than 4096 bytes.
Impact ===== If an attacker is able to exploit an application using libxml2 that parses remote resources, then this flaw could be used to execute arbitrary code.
Workaround ========= No w...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround