Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2018:3081-1 Moderate: libxml2 Denial Of Service Fix

suse
Calendar Grey October 9, 2018
Dist Suse Esm H88
An upgrade from SUSE addresses several vulnerabilities in OpenSSL, bolstering the system's defense against potential exploits.
An update that fixes four vulnerabilities is now available

Summary

This update for libxml2 fixes the following security issues: - CVE-2018-9251: The xz_decomp function allowed remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint (bsc#1088279). - CVE-2018-14567: Prevent denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint (bsc#1105166). - CVE-2018-14404: Prevent NULL pointer dereference in the xmlXPathCompOpEval() function when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case leading to a denial of service attack (bsc#1102046). - CVE-2017-18258: The xz_head function allowed remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because

References

#1088279 #1088601 #1102046 #1105166

Cross- CVE-2017-18258 CVE-2018-14404 CVE-2018-14567

CVE-2018-9251

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

SUSE CaaS Platform ALL

SUSE CaaS Platform 3.0

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2017-18258.html

https://www.suse.com/security/cve/CVE-2018-14404.html

https://www.suse.com/security/cve/CVE-2018-14567.html

https://www.suse.com/security/cve/CVE-2018-9251.html

https://bugzilla.suse.com/1088279

https://bugzilla.suse.com/1088601

https://bugzilla.suse.com/1102046

https://bugzilla.suse.com/1105166

Announcement ID: SUSE-SU-2018:3081-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here