Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update brings libxml2 to version 2.9.4.
These security issues were fixed:
- CVE-2016-3627: The xmlStringGetNodeList function in tree.c, when used in
recovery mode, allowed context-dependent attackers to cause a denial of
service (infinite recursion, stack consumption, and application crash)
via a crafted XML document (bsc#972335).
- CVE-2016-1833: libxml2 allowed remote attackers to execute arbitrary
code or cause a denial of service (memory corruption) via a crafted XML
document, a different vulnerability than CVE-2016-1834, CVE-2016-1836,
CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, and CVE-2016-1840
(bsc#981108).
- CVE-2016-1835: libxml2 allowed remote attackers to execute arbitrary
code or cause a denial of service (memory corruption) via a crafted XML
document (bsc#981109).
- CVE-2016-1837: libxml2 allowed remote attackers to execute arbitrary
code or cause a denial of service (memory corruption) via a...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 13.2:
zypper in -t patch openSUSE-2016-734=1
To bring your system up-to-date, use "zypper patch".
- openSUSE 13.2 (i586 x86_64):
libxml2-2-2.9.4-7.17.1
libxml2-2-debuginfo-2.9.4-7.17.1
libxml2-debugsource-2.9.4-7.17.1
libxml2-devel-2.9.4-7.17.1
libxml2-tools-2.9.4-7.17.1
libxml2-tools-debuginfo-2.9.4-7.17.1
python-libxml2-2.9.4-7.17.1
python-libxml2-debuginfo-2.9.4-7.17.1
python-libxml2-debugsource-2.9.4-7.17.1
- openSUSE 13.2 (x86_64):
libxml2-2-32bit-2.9.4-7.17.1
libxml2-2-debuginfo-32bit-2.9.4-7.17.1
libxml2-devel-32bit-2.9.4-7.17.1
- openSUSE 13.2 (noarch):
libxml2-doc-2.9.4-7.17.1
https://www.suse.com/security/cve/CVE-2016-1762.html
https://www.suse.com/security/cve/CVE-2016-1833.html
https://www.suse.com/security/cve/CVE-2016-1834.html
https://www.suse.com/security/cve/CVE-2016-1835.html
https://www.suse.com/security/cve/CVE-2016-1836.html
https://www.suse.com/security/cve/CVE-2016-1837.html
https://www.suse.com/security/cve/CVE-2016-1838.html
https://www.suse.com/security/cve/CVE-2016-1839.html
https://www.suse.com/security/cve/CVE-2016-1840.html
https://www.suse.com/security/cve/CVE-2016-3627.html
https://www.suse.com/security/cve/CVE-2016-3705.html
https://www.suse.com/security/cve/CVE-2016-4483.html
https://bugzilla.suse.com/972335
https://bugzilla.suse.com/975947
https://bugzilla.suse.com/978395
https://bugzilla.suse.com/981040
https://bugzilla.suse.com/981041
https://bugzilla.suse.com/981108
https://bugzilla.suse.com/981109
https://bugzilla.suse.com/981110
https://bugzilla.suse.com/981111
https://bugzilla.suse.com/981112
https://bugzilla.suse.com/981114
https://bugzilla.suse.co...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.