Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 14.04 LTS USN-2214-3 Moderate: Libxml2 Denial Of Service

Ubuntu Large Esm H500
USN-2214-1 introduced a regression in libxml2.
=========================================================================Ubuntu Security Notice USN-2214-3
June 17, 2014

libxml2 regression
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS
- Ubuntu 13.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

USN-2214-1 introduced a regression in libxml2.

Software Description:
- libxml2: GNOME XML library

Details:

USN-2214-1 fixed vulnerabilities in libxml2. The upstream fix introduced a
number of regressions. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

 Daniel Berrange discovered that libxml2 would incorrectly perform entity
 substitution even when requested not to. If a user or automated system were
 tricked into opening a specially crafted document, an attacker could
 possibly cause resource consumption, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libxml2                         2.9.1+dfsg1-3ubuntu4.3

Ubuntu 13.10:
  libxml2                         2.9.1+dfsg1-3ubuntu2.3

Ubuntu 12.04 LTS:
  libxml2                         2.7.8.dfsg-5.1ubuntu4.9

Ubuntu 10.04 LTS:
  libxml2                         2.7.6.dfsg-1ubuntu1.13

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2214-3
  https://ubuntu.com/security/notices/USN-2214-1
  https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/1321869

Package Information:
  https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.3
  https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu2.3
  https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.9
  https://launchpad.net/ubuntu/+source/libxml2/2.7.6.dfsg-1ubuntu1.13


Ubuntu 14.04 LTS USN-2214-3 Moderate: Libxml2 Denial Of Service

ubuntu
Calendar Grey June 17, 2014
Dist Ubuntu Esm H88
Make sure to upgrade your Ubuntu installations to fix the libxml2 vulnerabilities that were introduced by USN-2214-1 on June 17, 2014.
USN-2214-1 introduced a regression in libxml2.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libxml2 2.9.1+dfsg1-3ubuntu4.3 Ubuntu 13.10: libxml2 2.9.1+dfsg1-3ubuntu2.3 Ubuntu 12.04 LTS: libxml2 2.7.8.dfsg-5.1ubuntu4.9 Ubuntu 10.04 LTS: libxml2 2.7.6.dfsg-1ubuntu1.13 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2214-3

https://ubuntu.com/security/notices/USN-2214-1

https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/1321869

Severity
important
Lowest
Low
Medium
High
Critical

June 17, 2014

Package Information

https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.3 https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu2.3 https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.9 https://launchpad.net/ubuntu/+source/libxml2/2.7.6.dfsg-1ubuntu1.13

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here