SUSE-SU-2013:0743-1 -- Security update for libxml2
Description:
libxml2 has been updated to fix two security bugs. * CVE-2013-0338: Internal entity expansion within XMLwas not bounded, leading to simple small XML files beingable to cause "out of memory" denial of service conditions. * CVE-2012-5134: Heap-based buffer underflow in thexmlParseAttValueComplex function in parser.c in libxml2allowed remote attackers to cause a denial of service orpossibly execute arbitrary code via crafted entities in anXML document.