[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1461 libxml2 -- missing input validation

ID: oval:org.mitre.oval:def:8180Date: (C)2009-12-15   (M)2023-02-20
Class: PATCHFamily: unix




Brad Fitzpatrick discovered that the UTF-8 decoding functions of libxml2, the GNOME XML library, validate UTF-8 correctness insufficiently, which may lead to denial of service by forcing libxml2 into an infinite loop. For the old stable distribution (sarge), this problem has been fixed in version 2.6.16-7sarge1. For the stable distribution (etch), this problem has been fixed in version 2.6.27.dfsg-2. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your libxml2 packages.

Platform:
Debian 4.0
Debian 3.1
Product:
libxml2
Reference:
DSA-1461
CVE-2007-6284
CVE    1
CVE-2007-6284
CPE    3
cpe:/o:debian:debian_linux:4.x
cpe:/o:debian:debian_linux:3.1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies