Description: | Description:
The remote host is missing an update to libxml2 announced via advisory USN-673-1.
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS Ubuntu 7.10 Ubuntu 8.04 LTS Ubuntu 8.10
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
Drew Yao discovered that libxml2 did not correctly handle certain corrupt XML documents. If a user or automated system were tricked into processing a malicious XML document, a remote attacker could cause applications linked against libxml2 to enter an infinite loop, leading to a denial of service. (CVE-2008-4225)
Drew Yao discovered that libxml2 did not correctly handle large memory allocations. If a user or automated system were tricked into processing a very large XML document, a remote attacker could cause applications linked against libxml2 to crash, leading to a denial of service. (CVE-2008-4226)
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS: libxml2 2.6.24.dfsg-1ubuntu1.4
Ubuntu 7.10: libxml2 2.6.30.dfsg-2ubuntu1.4
Ubuntu 8.04 LTS: libxml2 2.6.31.dfsg-2ubuntu1.3
Ubuntu 8.10: libxml2 2.6.32.dfsg-4ubuntu1.1
After a standard system upgrade you need to restart your sessions to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-673-1
Risk factor : Critical
CVSS Score: 10.0
|