Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE Linux 10 SP4: 2013:1627-1 Important: libxml2 Denial Of Service Risk

suse
Calendar Grey November 4, 2013
Scroller Suse
The latest security patch for libxml2 resolves several issues to improve system stability and performance.
An update that fixes 8 vulnerabilities is now available

Summary

libxml2 has been updated to fix the following security issue: * CVE-2013-0338: libxml2 allowed context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity. Security Issue references: * CVE-2013-0338 * CVE-2013-0339 * CVE-2012-5134 * CVE-2012-2807 * CVE-2011-3102

References

#829077

Cross- CVE-2011-3102 CVE-2011-3919 CVE-2012-0841

CVE-2012-2807 CVE-2012-5134 CVE-2013-0338

CVE-2013-0339 CVE-2013-2877

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

https://www.suse.com/security/cve/CVE-2011-3102.html

https://www.suse.com/security/cve/CVE-2011-3919.html

https://www.suse.com/security/cve/CVE-2012-0841.html

https://www.suse.com/security/cve/CVE-2012-2807.html

https://www.suse.com/security/cve/CVE-2012-5134.html

https://www.suse.com/security/cve/CVE-2013-0338.html

https://www.suse.com/security/cve/CVE-2013-0339.html

https://www.suse.com/security/cve/CVE-2013-2877.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:1627-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.