Advisories ยป MGASA-2015-0358

Updated libxml2 packages fix security vulnerabilities

Publication date: 08 Sep 2015
Type: security
Affected Mageia releases : 4 , 5
CVE: CVE-2015-1819

Description

Updated libxml2 packages fix security vulnerability:

The xmlreader in libxml2 allows remote attackers to cause a denial of service
(memory consumption) via crafted XML data, related to an XML Entity Expansion
(XEE) attack (CVE-2015-1819).

The libxml2 package has been patched to fix this issue, as well as two
out-of-bounds read issues (bgo#744980, bgo#746048).
                

References

SRPMS

4/core

5/core