SUSE-SU-2013:0743-1: moderate: Security update for libxml2

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Thu May 2 14:04:22 MDT 2013


   SUSE Security Update: Security update for libxml2
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:0743-1
Rating:             moderate
References:         #793334 #805233 
Cross-References:   CVE-2013-0338 CVE-2013-0339
Affected Products:
                    SUSE Linux Enterprise Server 11 SP1 for VMware LTSS
                    SUSE Linux Enterprise Server 11 SP1 LTSS
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.

Description:


   libxml2 has been updated to fix two security bugs.

   * CVE-2013-0338: Internal entity expansion within XML
   was not bounded, leading to simple small XML files being
   able to cause "out of memory" denial of service conditions.
   * CVE-2012-5134: Heap-based buffer underflow in the
   xmlParseAttValueComplex function in parser.c in libxml2
   allowed remote attackers to cause a denial of service or
   possibly execute arbitrary code via crafted entities in an
   XML document.

   Security Issue references:

   * CVE-2013-0338
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0338
   >
   * CVE-2013-0339
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0339
   >


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server 11 SP1 for VMware LTSS:

      zypper in -t patch slessp1-libxml2-7630

   - SUSE Linux Enterprise Server 11 SP1 LTSS:

      zypper in -t patch slessp1-libxml2-7630

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server 11 SP1 for VMware LTSS (i586 x86_64):

      libxml2-2.7.6-0.23.1
      libxml2-doc-2.7.6-0.23.1
      libxml2-python-2.7.6-0.23.1

   - SUSE Linux Enterprise Server 11 SP1 for VMware LTSS (x86_64):

      libxml2-32bit-2.7.6-0.23.1

   - SUSE Linux Enterprise Server 11 SP1 LTSS (i586 s390x x86_64):

      libxml2-2.7.6-0.23.1
      libxml2-doc-2.7.6-0.23.1
      libxml2-python-2.7.6-0.23.1

   - SUSE Linux Enterprise Server 11 SP1 LTSS (s390x x86_64):

      libxml2-32bit-2.7.6-0.23.1


References:

   http://support.novell.com/security/cve/CVE-2013-0338.html
   http://support.novell.com/security/cve/CVE-2013-0339.html
   https://bugzilla.novell.com/793334
   https://bugzilla.novell.com/805233
   http://download.novell.com/patch/finder/?keywords=5dbce996d303d7d2a22bcc3cc845f1ea



More information about the sle-security-updates mailing list