Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.61535
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDVSA-2008:192 (libxml2)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to libxml2
announced via advisory MDVSA-2008:192.

A heap-based buffer overflow was found in how libxml2 handled long
XML entity names. If an application linked against libxml2 processed
untrusted malformed XML content, it could cause the application to
crash or possibly execute arbitrary code (CVE-2008-3529).

The updated packages have been patched to prevent this issue.
As well, the patch to fix CVE-2008-3281 has been updated to remove
the hard-coded entity limit that was set to 5M, instead using XML
entity density heuristics. Many thanks to Daniel Veillard of Red Hat
for his hard work in tracking down and dealing with the edge cases
discovered with the initial fix to this issue.

Affected: 2007.1, 2008.0, 2008.1, Corporate 3.0, Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2008:192

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-3529
1020855
http://securitytracker.com/id?1020855
247346
http://sunsolve.sun.com/search/document.do?assetkey=1-26-247346-1
261688
http://sunsolve.sun.com/search/document.do?assetkey=1-66-261688-1
265329
http://sunsolve.sun.com/search/document.do?assetkey=1-66-265329-1
31126
http://www.securityfocus.com/bid/31126
31558
http://secunia.com/advisories/31558
31855
http://secunia.com/advisories/31855
31860
http://secunia.com/advisories/31860
31868
http://secunia.com/advisories/31868
31982
http://secunia.com/advisories/31982
32265
http://secunia.com/advisories/32265
32280
http://secunia.com/advisories/32280
32807
http://secunia.com/advisories/32807
32974
http://secunia.com/advisories/32974
33715
http://secunia.com/advisories/33715
33722
http://secunia.com/advisories/33722
35056
http://secunia.com/advisories/35056
35074
http://secunia.com/advisories/35074
35379
http://secunia.com/advisories/35379
36173
http://secunia.com/advisories/36173
36235
http://secunia.com/advisories/36235
8798
https://www.exploit-db.com/exploits/8798
ADV-2008-2822
http://www.vupen.com/english/advisories/2008/2822
ADV-2009-1297
http://www.vupen.com/english/advisories/2009/1297
ADV-2009-1298
http://www.vupen.com/english/advisories/2009/1298
ADV-2009-1522
http://www.vupen.com/english/advisories/2009/1522
ADV-2009-1621
http://www.vupen.com/english/advisories/2009/1621
APPLE-SA-2009-05-12
http://lists.apple.com/archives/security-announce/2009/May/msg00000.html
APPLE-SA-2009-06-08-1
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
APPLE-SA-2009-06-17-1
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
DSA-1654
http://www.debian.org/security/2008/dsa-1654
GLSA-200812-06
http://security.gentoo.org/glsa/glsa-200812-06.xml
MDVSA-2008:192
http://www.mandriva.com/security/advisories?name=MDVSA-2008:192
RHSA-2008:0884
http://www.redhat.com/support/errata/RHSA-2008-0884.html
RHSA-2008:0886
http://www.redhat.com/support/errata/RHSA-2008-0886.html
SUSE-SR:2008:018
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html
TA09-133A
http://www.us-cert.gov/cas/techalerts/TA09-133A.html
USN-644-1
https://usn.ubuntu.com/644-1/
USN-815-1
http://www.ubuntu.com/usn/USN-815-1
http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-03-1
http://sunsolve.sun.com/search/document.do?assetkey=1-21-141243-01-1
http://support.apple.com/kb/HT3549
http://support.apple.com/kb/HT3550
http://support.apple.com/kb/HT3613
http://support.apple.com/kb/HT3639
http://support.avaya.com/elmodocs2/security/ASA-2008-400.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-025.htm
http://wiki.rpath.com/Advisories:rPSA-2008-0325
http://xmlsoft.org/news.html
https://bugzilla.redhat.com/show_bug.cgi?id=461015
libxml2-entitynames-bo(45085)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45085
oval:org.mitre.oval:def:11760
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11760
oval:org.mitre.oval:def:6103
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6103
Common Vulnerability Exposure (CVE) ID: CVE-2008-3281
1020728
http://www.securitytracker.com/id?1020728
20081031 VMSA-2008-0017 Updated ESX packages for libxml2, ucd-snmp, libtiff
http://www.securityfocus.com/archive/1/497962/100/0/threaded
30783
http://www.securityfocus.com/bid/30783
31566
http://secunia.com/advisories/31566
31590
http://secunia.com/advisories/31590
31728
http://secunia.com/advisories/31728
31748
http://secunia.com/advisories/31748
32488
http://secunia.com/advisories/32488
ADV-2008-2419
http://www.vupen.com/english/advisories/2008/2419
ADV-2008-2843
http://www.vupen.com/english/advisories/2008/2843
ADV-2008-2971
http://www.vupen.com/english/advisories/2008/2971
DSA-1631
http://www.debian.org/security/2008/dsa-1631
FEDORA-2008-7395
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00347.html
FEDORA-2008-7594
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00261.html
MDVSA-2008:180
http://www.mandriva.com/security/advisories?name=MDVSA-2008:180
RHSA-2008:0836
https://rhn.redhat.com/errata/RHSA-2008-0836.html
USN-640-1
http://www.ubuntu.com/usn/usn-640-1
[Security-announce] 20081030 VMSA-2008-0017 Updated ESX packages for libxml2, ucd-snmp, libtiff
http://lists.vmware.com/pipermail/security-announce/2008/000039.html
[xml] 20080820 Security fix for libxml2
http://mail.gnome.org/archives/xml/2008-August/msg00034.html
http://svn.gnome.org/viewvc/libxml2?view=revision&revision=3772
http://www.vmware.com/security/advisories/VMSA-2008-0017.html
https://bugzilla.redhat.com/show_bug.cgi?id=458086
oval:org.mitre.oval:def:6496
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6496
oval:org.mitre.oval:def:9812
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9812
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.