Date:         Mon, 3 Aug 2015 18:11:09 +0000
Reply-To:     scientific-linux-users@listserv.fnal.gov
Sender:       Security Errata for Scientific Linux
              
From:         Connie Sieh 
Subject:      Security ERRATA Low: libxml2 on SL6.x i386/x86_64
MIME-Version: 1.0
Message-ID:  <20150803181109.24587.80876@slpackages.fnal.gov>

Synopsis:          Low: libxml2 security and bug fix update
Advisory ID:       SLSA-2015:1419-1
Issue Date:        2015-07-22
CVE Numbers:       CVE-2015-1819
--

A denial of service flaw was found in the way the libxml2 library parsed
certain XML files. An attacker could provide a specially crafted XML file
that, when parsed by an application using libxml2, could cause that
application to use an excessive amount of memory. (CVE-2015-1819)

This issue was discovered by Florian Weimer of Red Hat Product Security.

This update also fixes the following bug:

This update fixes an error that occurred when running a test case for the
serialization of HTML documents.

The desktop must be restarted (log out, then log back in) for this update
to take effect.
--

SL6
  x86_64
    libxml2-2.7.6-20.el6.i686.rpm
    libxml2-2.7.6-20.el6.x86_64.rpm
    libxml2-debuginfo-2.7.6-20.el6.i686.rpm
    libxml2-debuginfo-2.7.6-20.el6.x86_64.rpm
    libxml2-python-2.7.6-20.el6.x86_64.rpm
    libxml2-devel-2.7.6-20.el6.i686.rpm
    libxml2-devel-2.7.6-20.el6.x86_64.rpm
    libxml2-static-2.7.6-20.el6.x86_64.rpm
  i386
    libxml2-2.7.6-20.el6.i686.rpm
    libxml2-debuginfo-2.7.6-20.el6.i686.rpm
    libxml2-python-2.7.6-20.el6.i686.rpm
    libxml2-devel-2.7.6-20.el6.i686.rpm
    libxml2-static-2.7.6-20.el6.i686.rpm

- Scientific Linux Development Team

SciLinux: CVE-2015-1819 Low: libxml2 SL6.x i386/x86_64

Low: libxml2 security and bug fix update

Summary

Low: libxml2 security and bug fix update



Security Fixes

Severity
Advisory ID: SLSA-2015:1419-1
Issued Date: : 2015-07-22
CVE Numbers: CVE-2015-1819
A denial of service flaw was found in the way the libxml2 library parsed