Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE 15: SUSE-SU-2018:3080-1 Moderate: libxml2 Denial Of Service

suse
Calendar Grey October 9, 2018
Dist Suse Esm H88
SUSE has released a security update for libxml2 to address vulnerabilities related to denial of service and enhance overall system dependability.
An update that fixes three vulnerabilities is now available

Summary

This update for libxml2 fixes the following security issues: - CVE-2018-9251: The xz_decomp function allowed remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint (bsc#1088279) - CVE-2018-14567: Prevent denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint (bsc#1105166) - CVE-2018-14404: Prevent NULL pointer dereference in the xmlXPathCompOpEval() function when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case leading to a denial of service attack (bsc#1102046) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1088279 #1102046 #1105166

Cross- CVE-2018-14404 CVE-2018-14567 CVE-2018-9251

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-14404.html

https://www.suse.com/security/cve/CVE-2018-14567.html

https://www.suse.com/security/cve/CVE-2018-9251.html

https://bugzilla.suse.com/1088279

https://bugzilla.suse.com/1102046

https://bugzilla.suse.com/1105166

Announcement ID: SUSE-SU-2018:3080-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here