SUSE-SU-2017:1366-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1366-1
SUSE-SU-2017:1366-1
Summary: Security update for libxml2
Details: This update for libxml2 fixes the following issues: * Fix NULL dereference in xpointer.c when in recovery mode [bsc#1014873] * CVE-2016-9597: An XML document with many opening tags could have caused a overflow of the stack not detected by the recursion limits, allowing for DoS (bsc#1017497) * CVE-2014-0191: External parameter entity loaded when entity substitution is disabled could cause a DoS. (bsc#876652) * CVE-2016-9318: XML External Entity (XXE) could be abused via crafted document. (bsc#1010675)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171366-1/, https://bugzilla.suse.com/1010675, https://bugzilla.suse.com/1013930, https://bugzilla.suse.com/1014873, https://bugzilla.suse.com/1017497, https://bugzilla.suse.com/876652, https://www.suse.com/security/cve/CVE-2014-0191, https://www.suse.com/security/cve/CVE-2016-9318, https://www.suse.com/security/cve/CVE-2016-9597
Affected packages
Package
Name: libxml2
Purl: pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
