Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in libxml2
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in libxml2
ID: USN-2812-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04, Ubuntu 15.10
Datum: Mo, 16. November 2015, 22:46
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7941
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1819
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7942
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8035
Applikationen: libxml2

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============6818530372813501826==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="xaBHlkKK0lhShbdjTdTWvKAsQcsvlv6A3"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--xaBHlkKK0lhShbdjTdTWvKAsQcsvlv6A3
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2812-1
November 16, 2015

libxml2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in libxml2.

Software Description:
- libxml2: GNOME XML library

Details:

Florian Weimer discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause resource consumption,
resulting in a denial of service. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-1819)

Michal Zalewski discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause libxml2 to crash,
resulting in a denial of service. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-7941)

Kostya Serebryany discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-7942)

Gustavo Grieco discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause libxml2 to crash,
resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2015-8035)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
libxml2 2.9.2+zdfsg1-4ubuntu0.1

Ubuntu 15.04:
libxml2 2.9.2+dfsg1-3ubuntu0.1

Ubuntu 14.04 LTS:
libxml2 2.9.1+dfsg1-3ubuntu4.5

Ubuntu 12.04 LTS:
libxml2 2.7.8.dfsg-5.1ubuntu4.12

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2812-1
CVE-2015-1819, CVE-2015-7941, CVE-2015-7942, CVE-2015-8035

Package Information:
https://launchpad.net/ubuntu/+source/libxml2/2.9.2+zdfsg1-4ubuntu0.1
https://launchpad.net/ubuntu/+source/libxml2/2.9.2+dfsg1-3ubuntu0.1
https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5
https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.12



--xaBHlkKK0lhShbdjTdTWvKAsQcsvlv6A3
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWSie3AAoJEGVp2FWnRL6T5KoP/jdnAQVuRvSE2nn06TrwdNy2
8u2Azjg35e6tNIvrzGP/PXfXROXCuOEfi+NHr8hVi0h+nlc18KyHlCiw6PYjcOyC
uWIhJ7cNQkuXCdfHqVJoD0DjEXrLq8I5/dcMnYR8YHH+4QuexGnnVn2x77jRifak
FKHWwmQ//Fzb4B3s2DmnhjdR7mZEhdeNRLOiMfQHdivATgdKKE68tpx0vCU9cuHn
V+ldPlJk8ZiBS92GDi4yhrH4My6TR9H5HVU0FzDGv6KFNulY/Ip9GaVTbHrRJm4Q
OjopGt8NNy8ECRz7MmiDwlyTtLPmzhG3WCX8x93iQ4kb1FBqBqcCce55MZPqCVAx
QcmC7A2BuU63oCadyGgpJN/i6q38cfbFaqonOY8l8GLbAJ9ml9BBFws01LvAjpUC
8R6IWzA6aLBu5Nt1cBMO2DbdfRJmB0KfjNJwciopy5T4FAhnyYhCejpMHxYcbVlX
dCtRUm6psKgKgWivwLiYsb5UnSNmzXN1QnUppzLWFM6y6za7zYdrIatCxQQn0zvC
SVn5PfpczcN2vbTPZE5NjyItHWpVK0H2ozmKwPkK86tS7YGR/sL0ycTkoHg1Nfud
rR6dMNpRnIMmF93gL1Babvwo8v299iun8t7KwyjX8DTQcVa1Kj/nmUzRUC+QjeBO
vqM1oDvgRv1te10OU0HQ
=l9Fe
-----END PGP SIGNATURE-----

--xaBHlkKK0lhShbdjTdTWvKAsQcsvlv6A3--


--===============6818530372813501826==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============6818530372813501826==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung