RedHat: RHSA-2015-2550:01 Moderate: libxml2 security update
Summary
The libxml2 library is a development toolbox providing the implementation
of various XML standards.
Several denial of service flaws were found in libxml2, a library providing
support for reading, modifying, and writing XML and HTML files. A remote
attacker could provide a specially crafted XML or HTML file that, when
processed by an application using libxml2, would cause that application to
use an excessive amount of CPU, leak potentially sensitive information, or
in certain cases crash the application. (CVE-2015-1819, CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499, CVE-2015-7500 CVE-2015-7941,
CVE-2015-7942, CVE-2015-8241, CVE-2015-8242, CVE-2015-8317, BZ#1213957,
BZ#1281955)
Red Hat would like to thank the GNOME project for reporting CVE-2015-7497,
CVE-2015-7498, CVE-2015-7499, CVE-2015-7500, CVE-2015-8241, CVE-2015-8242,
and CVE-2015-8317. Upstream acknowledges Kostya Serebryany of Google as the
original reporter of CVE-2015-7497, CVE-2015-7498, CVE-2015-7499, and
CVE-2015-7500; Hugh Davenport as the original reporter of CVE-2015-8241 and
CVE-2015-8242; and Hanno Boeck as the original reporter of CVE-2015-8317.
The CVE-2015-1819 issue was discovered by Florian Weimer of Red Hat
Product Security.
All libxml2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.
Summary
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2015-1819 https://access.redhat.com/security/cve/CVE-2015-5312 https://access.redhat.com/security/cve/CVE-2015-7497 https://access.redhat.com/security/cve/CVE-2015-7498 https://access.redhat.com/security/cve/CVE-2015-7499 https://access.redhat.com/security/cve/CVE-2015-7500 https://access.redhat.com/security/cve/CVE-2015-7941 https://access.redhat.com/security/cve/CVE-2015-7942 https://access.redhat.com/security/cve/CVE-2015-8241 https://access.redhat.com/security/cve/CVE-2015-8242 https://access.redhat.com/security/cve/CVE-2015-8317 https://access.redhat.com/security/updates/classification/#moderate
Package List
Red Hat Enterprise Linux Client (v. 7):
Source:
libxml2-2.9.1-6.el7_2.2.src.rpm
x86_64:
libxml2-2.9.1-6.el7_2.2.i686.rpm
libxml2-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.i686.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-python-2.9.1-6.el7_2.2.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
libxml2-debuginfo-2.9.1-6.el7_2.2.i686.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-devel-2.9.1-6.el7_2.2.i686.rpm
libxml2-devel-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-static-2.9.1-6.el7_2.2.i686.rpm
libxml2-static-2.9.1-6.el7_2.2.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
libxml2-2.9.1-6.el7_2.2.src.rpm
x86_64:
libxml2-2.9.1-6.el7_2.2.i686.rpm
libxml2-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.i686.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-python-2.9.1-6.el7_2.2.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
libxml2-debuginfo-2.9.1-6.el7_2.2.i686.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-devel-2.9.1-6.el7_2.2.i686.rpm
libxml2-devel-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-static-2.9.1-6.el7_2.2.i686.rpm
libxml2-static-2.9.1-6.el7_2.2.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
libxml2-2.9.1-6.el7_2.2.src.rpm
aarch64:
libxml2-2.9.1-6.el7_2.2.aarch64.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.aarch64.rpm
libxml2-devel-2.9.1-6.el7_2.2.aarch64.rpm
libxml2-python-2.9.1-6.el7_2.2.aarch64.rpm
ppc64:
libxml2-2.9.1-6.el7_2.2.ppc.rpm
libxml2-2.9.1-6.el7_2.2.ppc64.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.ppc.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.ppc64.rpm
libxml2-devel-2.9.1-6.el7_2.2.ppc.rpm
libxml2-devel-2.9.1-6.el7_2.2.ppc64.rpm
libxml2-python-2.9.1-6.el7_2.2.ppc64.rpm
ppc64le:
libxml2-2.9.1-6.el7_2.2.ppc64le.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.ppc64le.rpm
libxml2-devel-2.9.1-6.el7_2.2.ppc64le.rpm
libxml2-python-2.9.1-6.el7_2.2.ppc64le.rpm
s390x:
libxml2-2.9.1-6.el7_2.2.s390.rpm
libxml2-2.9.1-6.el7_2.2.s390x.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.s390.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.s390x.rpm
libxml2-devel-2.9.1-6.el7_2.2.s390.rpm
libxml2-devel-2.9.1-6.el7_2.2.s390x.rpm
libxml2-python-2.9.1-6.el7_2.2.s390x.rpm
x86_64:
libxml2-2.9.1-6.el7_2.2.i686.rpm
libxml2-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.i686.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-devel-2.9.1-6.el7_2.2.i686.rpm
libxml2-devel-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-python-2.9.1-6.el7_2.2.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
aarch64:
libxml2-debuginfo-2.9.1-6.el7_2.2.aarch64.rpm
libxml2-static-2.9.1-6.el7_2.2.aarch64.rpm
ppc64:
libxml2-debuginfo-2.9.1-6.el7_2.2.ppc.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.ppc64.rpm
libxml2-static-2.9.1-6.el7_2.2.ppc.rpm
libxml2-static-2.9.1-6.el7_2.2.ppc64.rpm
ppc64le:
libxml2-debuginfo-2.9.1-6.el7_2.2.ppc64le.rpm
libxml2-static-2.9.1-6.el7_2.2.ppc64le.rpm
s390x:
libxml2-debuginfo-2.9.1-6.el7_2.2.s390.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.s390x.rpm
libxml2-static-2.9.1-6.el7_2.2.s390.rpm
libxml2-static-2.9.1-6.el7_2.2.s390x.rpm
x86_64:
libxml2-debuginfo-2.9.1-6.el7_2.2.i686.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-static-2.9.1-6.el7_2.2.i686.rpm
libxml2-static-2.9.1-6.el7_2.2.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
libxml2-2.9.1-6.el7_2.2.src.rpm
x86_64:
libxml2-2.9.1-6.el7_2.2.i686.rpm
libxml2-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.i686.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-devel-2.9.1-6.el7_2.2.i686.rpm
libxml2-devel-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-python-2.9.1-6.el7_2.2.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
libxml2-debuginfo-2.9.1-6.el7_2.2.i686.rpm
libxml2-debuginfo-2.9.1-6.el7_2.2.x86_64.rpm
libxml2-static-2.9.1-6.el7_2.2.i686.rpm
libxml2-static-2.9.1-6.el7_2.2.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
Updated libxml2 packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having Moderate securityimpact. Common Vulnerability Scoring System (CVSS) base scores, which givedetailed severity ratings, are available for each vulnerability from theCVE links in the References section.
Topic
Relevant Releases Architectures
Red Hat Enterprise Linux Client (v. 7) - x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
Bugs Fixed
1211278 - CVE-2015-1819 libxml2: denial of service processing a crafted XML document
1213957 - libxml2: out-of-bounds memory access when parsing an unclosed HTML comment
1274222 - CVE-2015-7941 libxml2: Out-of-bounds memory access
1276297 - CVE-2015-7942 libxml2: heap-based buffer overflow in xmlParseConditionalSections()
1276693 - CVE-2015-5312 libxml2: CPU exhaustion when processing specially crafted XML input
1281862 - CVE-2015-7497 libxml2: Heap-based buffer overflow in xmlDictComputeFastQKey
1281879 - CVE-2015-7498 libxml2: Heap-based buffer overflow in xmlParseXmlDecl
1281925 - CVE-2015-7499 libxml2: Heap-based buffer overflow in xmlGROW
1281930 - CVE-2015-8317 libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration
1281936 - CVE-2015-8241 libxml2: Buffer overread with XML parser in xmlNextChar
1281943 - CVE-2015-7500 libxml2: Heap buffer overflow in xmlParseMisc
1281950 - CVE-2015-8242 libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode
1281955 - libxml2: Multiple out-of-bounds reads in xmlDictComputeFastKey.isra.2 and xmlDictAddString.isra.O