Oval Definition:oval:com.redhat.rhsa:def:20140513
Revision Date:2014-05-19Version:637
Title:RHSA-2014:0513: libxml2 security update (Moderate)
Description:The libxml2 library is a development toolbox providing the implementation of various XML standards.

  • It was discovered that libxml2 loaded external parameter entities even when entity substitution was disabled. A remote attacker able to provide a specially crafted XML file to an application linked against libxml2 could use this flaw to conduct XML External Entity (XXE) attacks, possibly resulting in a denial of service or an information leak on the system. (CVE-2014-0191)

  • An out-of-bounds read flaw was found in the way libxml2 detected the end of an XML file. A remote attacker could provide a specially crafted XML file that, when processed by an application linked against libxml2, could cause the application to crash. (CVE-2013-2877)

    The CVE-2014-0191 issue was discovered by Daniel P. Berrange of Red Hat.

    All libxml2 users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. The desktop must be restarted (log out, then log back in) for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-2877
    CVE-2013-2877
    CVE-2014-0191
    CVE-2014-0191
    RHSA-2014:0513
    RHSA-2014:0513-00
    RHSA-2014:0513-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • libxml2 is earlier than 0:2.7.6-14.el6_5.1
  • AND libxml2 is signed with Red Hat redhatrelease2 key
  • libxml2-devel is earlier than 0:2.7.6-14.el6_5.1
  • AND libxml2-devel is signed with Red Hat redhatrelease2 key
  • libxml2-python is earlier than 0:2.7.6-14.el6_5.1
  • AND libxml2-python is signed with Red Hat redhatrelease2 key
  • libxml2-static is earlier than 0:2.7.6-14.el6_5.1
  • AND libxml2-static is signed with Red Hat redhatrelease2 key
  • BACK