Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

SUSE: 2018:0170-1 Important: perl-XML-LibXML Remote Code Issue

suse
Calendar Grey January 22, 2018
Scroller Suse
SUSE Security Patch for perl-XML-LibXML mitigates an urgent issue and outlines remediation steps.
An update that fixes one vulnerability is now available.

Summary

This update for perl-XML-LibXML fixes the following issues: - CVE-2017-10672: A use-after-free allowed remote attackers to potentially execute arbitrary code by controlling the arguments to a replaceChild call (bsc#1046848) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-perl-XML-LibXML-13426=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-perl-XML-LibXML-13426=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-perl-XML-LibXML-13426=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-perl-XML-LibXML-13426=1 - SUSE Linux Enterprise Debuginfo 11-SP3:

References

#1046848

Cross- CVE-2017-10672

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2017-10672.html

https://bugzilla.suse.com/1046848

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0170-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.