SCIENTIFIC-LINUX-ERRATA Archives

September 2008

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Thu, 11 Sep 2008 16:19:55 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (55 lines)
Synopsis:	Important: libxml2 security update
Issue date:	2008-09-11
CVE Names:	CVE-2008-3529

A heap-based buffer overflow flaw was found in the way libxml2 handled long
XML entity names. If an application linked against libxml2 processed
untrusted malformed XML content, it could cause the application to crash
or, possibly, execute arbitrary code. (CVE-2008-3529)

SL 3.0.x

      SRPMS:
libxml2-2.5.10-13.src.rpm
      i386:
libxml2-2.5.10-13.i386.rpm
libxml2-devel-2.5.10-13.i386.rpm
libxml2-python-2.5.10-13.i386.rpm
      x86_64:
libxml2-2.5.10-13.i386.rpm
libxml2-2.5.10-13.x86_64.rpm
libxml2-devel-2.5.10-13.x86_64.rpm
libxml2-python-2.5.10-13.x86_64.rpm

SL 4.x

      SRPMS:
libxml2-2.6.16-12.5.src.rpm
      i386:
libxml2-2.6.16-12.5.i386.rpm
libxml2-devel-2.6.16-12.5.i386.rpm
libxml2-python-2.6.16-12.5.i386.rpm
      x86_64:
libxml2-2.6.16-12.5.i386.rpm
libxml2-2.6.16-12.5.x86_64.rpm
libxml2-devel-2.6.16-12.5.x86_64.rpm
libxml2-python-2.6.16-12.5.x86_64.rpm

SL 5.x

      SRPMS:
libxml2-2.6.26-2.1.2.6.src.rpm
      i386:
libxml2-2.6.26-2.1.2.6.i386.rpm
libxml2-devel-2.6.26-2.1.2.6.i386.rpm
libxml2-python-2.6.26-2.1.2.6.i386.rpm
      x86_64:
libxml2-2.6.26-2.1.2.6.i386.rpm
libxml2-2.6.26-2.1.2.6.x86_64.rpm
libxml2-devel-2.6.26-2.1.2.6.i386.rpm
libxml2-devel-2.6.26-2.1.2.6.x86_64.rpm
libxml2-python-2.6.26-2.1.2.6.x86_64.rpm

-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2