Advisories ยป MGASA-2016-0187

Updated libxml2 packages fix security vulnerability

Publication date: 20 May 2016
Modification date: 20 May 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-3627 , CVE-2016-3705

Description

When running in recovery mode, certain invalid XML documents would trigger
an infinite recursion in libxml2 that ran until all stack space was
exhausted. This vulnerability could have been used to facilitate a
denial-of-sevice attack (CVE-2016-3627).

libxml2 limits the number of recursions an XML document can contain so to
protect against the "Billion Laughs" denial-of-service attack.
Unfortunately, the underlying counter was not incremented properly in all
necessary locations. Therefore, specially crafted XML documents could
exhaust all available stack space and crash the XML parser without running
into the recursion limit (CVE-2016-3705).
                

References

SRPMS

5/core