SUSE-SU-2017:1557-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1557-1
SUSE-SU-2017:1557-1
Summary: Security update for libxml2
Details: This update for libxml2 fixes the following issues: Security issues fixed: - CVE-2017-9050: heap-based buffer overflow (xmlDictAddString func) [bsc#1039069, bsc#1039661] - CVE-2017-9049: heap-based buffer overflow (xmlDictComputeFastKey func) [bsc#1039066] - CVE-2017-9048: stack overflow vulnerability (xmlSnprintfElementContent func) [bsc#1039063] - CVE-2017-9047: stack overflow vulnerability (xmlSnprintfElementContent func) [bsc#1039064] A clarification for the previously released update: For CVE-2016-9318 we decided not to ship a fix since it can break existing setups. Please take appropriate actions if you parse untrusted XML files and use the new -noxxe flag if possible (bnc#1010675, bnc#1013930).
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171557-1/, https://bugzilla.suse.com/1010675, https://bugzilla.suse.com/1013930, https://bugzilla.suse.com/1039063, https://bugzilla.suse.com/1039064, https://bugzilla.suse.com/1039066, https://bugzilla.suse.com/1039069, https://bugzilla.suse.com/1039661, https://www.suse.com/security/cve/CVE-2016-9318, https://www.suse.com/security/cve/CVE-2017-9047, https://www.suse.com/security/cve/CVE-2017-9048, https://www.suse.com/security/cve/CVE-2017-9049, https://www.suse.com/security/cve/CVE-2017-9050
Affected packages
Package
Name: libxml2
Purl: pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
