Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2019:13985-1 Moderate: libxml2 Denial Of Service Issue

suse
Calendar Grey March 22, 2019
Dist Suse Esm H88
SUSE has released a vital Security Update that tackles severe vulnerabilities in libxml2, enhancing the security of systems. Discover the importance of this update now.
An update that solves two vulnerabilities and has two fixes is now available

Summary

This update for libxml2 fixes the following issues: Security issue fixed: - CVE-2018-14404: Prevent NULL pointer dereference in the xmlXPathCompOpEval() function when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case leading to a denial of service attack (bsc#1102046) Other Issue fixed: - Fixed a bug related to the fix for CVE-2016-9318 which allowed xsltproc to access the internet even when --nonet was given and also was making docbook-xsl-stylesheets to have incomplete xml catalog file (bsc#1010675, bsc#1126613 and bsc#1110146). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1010675 #1102046 #1110146 #1126613

Cross- CVE-2016-9318 CVE-2018-14404

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-9318.html

https://www.suse.com/security/cve/CVE-2018-14404.html

https://bugzilla.suse.com/1010675

https://bugzilla.suse.com/1102046

https://bugzilla.suse.com/1110146

https://bugzilla.suse.com/1126613

Announcement ID: SUSE-SU-2019:13985-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here