Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 12.04 ESM USN-3424-2 Critical: Libxml2 Multiple Threats

ubuntu
Calendar Grey October 10, 2017
Scroller Ubuntu
Ubuntu Security Notice USN-3424-2 addresses critical vulnerabilities in libxml2, prevalent in XML processing applications, urging users to upgrade affected packages.
Several security issues were fixed in libxml2.

Summary

Several security issues were fixed in libxml2.

Software Description:

- libxml2: GNOME XML library

Details:

USN-3424-1 fixed several vulnerabilities in libxml2. This update

provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that a type confusion error existed in libxml2. An

 attacker could use this to specially construct XML data that

 could cause a denial of service or possibly execute arbitrary

 code. (CVE-2017-0663)

 It was discovered that libxml2 did not properly validate parsed entity

 references. An attacker could use this to specially construct XML

 data that could expose sensitive information. (CVE-2017-7375)

 It was discovered that a buffer overflow existed in libxml2 when

 handling HTTP redirects. An attacker could use this to specially

 construct XML data that could cause a denial of service or possibly

 execute arbitrary code. (CVE-2017-7376)

 Marcel Böhme and Van-Thuan Pha...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  libxml2                         2.7.8.dfsg-5.1ubuntu4.18

In general, a standard system update will make all the necessary
changes.

References

  https://ubuntu.com/security/notices/USN-3424-2

  https://ubuntu.com/security/notices/USN-3424-1

  CVE-2017-0663, CVE-2017-7375, CVE-2017-7376, CVE-2017-9047,

  CVE-2017-9048, CVE-2017-9049, CVE-2017-9050

Severity
critical
Lowest
Low
Medium
High
Critical

October 10, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.