security advisorydenial of servicedebian
The XML parsers used by XMLBeans did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include the possibility for XML Entity Expansion attacks which could lead to a denial-of-service. This update implements sensible defaults for the XML parsers to prevent these kind . -------------------------------------------------------------------------Debian LTS Advisory DLA-2693-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 28, 2021 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : xmlbeans Version : 2.6.0+dfsg-1+deb9u1 CVE ID : CVE-2021-23926 The XML parsers used by XMLBeans did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include the possibility for XML Entity Expansion attacks which could lead to a denial-of-service. This update implements sensible defaults for the XML parsers to prevent these kind of attacks. For Debian 9 stretch, this problem has been fixed in version 2.6.0+dfsg-1+deb9u1. We recommend that you upgrade your xmlbeans packages. For the detailed security status of xmlbeans please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/xmlbeans Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2700-1 tackles vulnerabilities in libxml2 to improve stability.. xmlbeans security update, denial of service, debian advisory, xml entity expansion. . LinuxSecurity.com Team
Jun 28, 2021
Debian LTS