Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 12.10 USN-1656-1 Critical: Libxml2 Buffer Underflow Exploit

ubuntu
Calendar Grey December 6, 2012
Scroller Ubuntu
Ubuntu Security Notice USN-1656-1 highlights a security flaw in libxml2 that could lead to application crashes or the potential execution of unauthorized code.
Applications using libxml2 could be made to crash or run programs asyour login if they opened a specially crafted file.

Summary

Applications using libxml2 could be made to crash or run programs as

your login if they opened a specially crafted file.

Software Description:

- libxml2: GNOME XML library

Details:

It was discovered that libxml2 had a heap-based buffer underflow

when parsing entities. If a user or automated system were tricked into

processing a specially crafted XML document, applications linked against

libxml2 could be made to crash or possibly execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  libxml2                         2.8.0+dfsg1-5ubuntu2.1

Ubuntu 12.04 LTS:
  libxml2                         2.7.8.dfsg-5.1ubuntu4.3

Ubuntu 11.10:
  libxml2                         2.7.8.dfsg-4ubuntu0.5

Ubuntu 10.04 LTS:
  libxml2                         2.7.6.dfsg-1ubuntu1.7

Ubuntu 8.04 LTS:
  libxml2                         2.6.31.dfsg-2ubuntu1.11

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1656-1

CVE-2012-5134

Severity
critical
Lowest
Low
Medium
High
Critical

December 06, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.