Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Gentoo: 202310-01 Urgent: OpenSSL Security Vulnerability Notification

gentoo
Calendar Grey March 6, 2004
Dist Gentoo Esm H88
Mitigating Libxml2 buffer overflow threats in Gentoo to avert execution risk of malicious code.
A buffer overflow has been discovered in libxml2 versions prior to 2.6.6 which may be exploited by an attacker allowing the execution of arbitrary code

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200403-01
~                                            https://security.gentoo.org/

~ Severity: Normal ~ Title: Libxml2 URI Parsing Buffer Overflow Vulnerabilities ~ Date: March 06, 2004 ~ Bugs: #42735 ~ ID: 200403-01

Synopsis ======= A buffer overflow has been discovered in libxml2 versions prior to 2.6.6 which may be exploited by an attacker allowing the execution of arbitrary code.
========== Yuuichi Teranishi discovered a flaw in libxml2 versions prior to 2.6.6. When the libxml2 library fetches a remote resource via FTP or HTTP, libxml2 uses parsing routines that can overflow a buffer caused by improper bounds checking if they are passed a URL longer than 4096 bytes.
Impact ===== If an attacker is able to exploit an application using libxml2 that parses remote resources, then this flaw could be used to execute arbitrary code.
Workaround ========= No w...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3312490_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here