Low: libxml2 security and bug fix update
Date: Mon, 3 Aug 2015 18:11:09 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
From: Connie Sieh
Subject: Security ERRATA Low: libxml2 on SL6.x i386/x86_64
MIME-Version: 1.0
Message-ID: <20150803181109.24587.80876@slpackages.fnal.gov>
Synopsis: Low: libxml2 security and bug fix update
Advisory ID: SLSA-2015:1419-1
Issue Date: 2015-07-22
CVE Numbers: CVE-2015-1819
--
A denial of service flaw was found in the way the libxml2 library parsed
certain XML files. An attacker could provide a specially crafted XML file
that, when parsed by an application using libxml2, could cause that
application to use an excessive amount of memory. (CVE-2015-1819)
This issue was discovered by Florian Weimer of Red Hat Product Security.
This update also fixes the following bug:
This update fixes an error that occurred when running a test case for the
serialization of HTML documents.
The desktop must be restarted (log out, then log back in) for this update
to take effect.
--
SL6
x86_64
libxml2-2.7.6-20.el6.i686.rpm
libxml2-2.7.6-20.el6.x86_64.rpm
libxml2-debuginfo-2.7.6-20.el6.i686.rpm
libxml2-debuginfo-2.7.6-20.el6.x86_64.rpm
libxml2-python-2.7.6-20.el6.x86_64.rpm
libxml2-devel-2.7.6-20.el6.i686.rpm
libxml2-devel-2.7.6-20.el6.x86_64.rpm
libxml2-static-2.7.6-20.el6.x86_64.rpm
i386
libxml2-2.7.6-20.el6.i686.rpm
libxml2-debuginfo-2.7.6-20.el6.i686.rpm
libxml2-python-2.7.6-20.el6.i686.rpm
libxml2-devel-2.7.6-20.el6.i686.rpm
libxml2-static-2.7.6-20.el6.i686.rpm
- Scientific Linux Development Team