Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2018.0050
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2018-0050)
Zusammenfassung:The remote host is missing an update for the 'libxml2' package(s) announced via the MGASA-2018-0050 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'libxml2' package(s) announced via the MGASA-2018-0050 advisory.

Vulnerability Insight:
Integer overflow in memory debug code in libxml2 before 2.9.5
(CVE-2017-5130).

It was discovered that libxml2 incorrecty handled certain files. An
attacker could use this issue with specially constructed XML data to cause
libxml2 to consume resources, leading to a denial of service
(CVE-2017-15412).

Wei Lei discovered that libxml2 incorrecty handled certain parameter
entities. An attacker could use this issue with specially constructed XML
data to cause libxml2 to consume resources, leading to a denial of service
(CVE-2017-16932).

The libxml2 package has been updated to version 2.9.7 to fix these issues
and several other bugs.

Also, the perl-XML-LibXML package has been updated to version 2.13.200 to
allow it to be rebuilt against the updated libxml2.

Affected Software/OS:
'libxml2' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-15412
Debian Security Information: DSA-4086 (Google Search)
https://www.debian.org/security/2018/dsa-4086
https://security.gentoo.org/glsa/201801-03
https://bugzilla.gnome.org/show_bug.cgi?id=783160
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
https://crbug.com/727039
https://lists.debian.org/debian-lts-announce/2017/12/msg00014.html
RedHat Security Advisories: RHSA-2017:3401
https://access.redhat.com/errata/RHSA-2017:3401
RedHat Security Advisories: RHSA-2018:0287
https://access.redhat.com/errata/RHSA-2018:0287
http://www.securitytracker.com/id/1040348
Common Vulnerability Exposure (CVE) ID: CVE-2017-16932
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
https://lists.debian.org/debian-lts-announce/2017/11/msg00041.html
https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html
https://usn.ubuntu.com/3739-1/
Common Vulnerability Exposure (CVE) ID: CVE-2017-5130
BugTraq ID: 101482
http://www.securityfocus.com/bid/101482
https://security.gentoo.org/glsa/201710-24
http://bugzilla.gnome.org/show_bug.cgi?id=783026
https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html
https://crbug.com/722079
https://git.gnome.org/browse/libxml2/commit/?id=897dffbae322b46b83f99a607d527058a72c51ed
https://www.oracle.com/security-alerts/cpuapr2020.html
https://lists.debian.org/debian-lts-announce/2017/11/msg00034.html
RedHat Security Advisories: RHSA-2017:2997
https://access.redhat.com/errata/RHSA-2017:2997
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.