Oval Definition:oval:org.mitre.oval:def:27149
Revision Date:2015-04-13Version:12
Title:RHSA-2014:1655: libxml2 security update (Moderate)
Description:The libxml2 library is a development toolbox providing the implementationof various XML standards.A denial of service flaw was found in libxml2, a library providing supportto read, modify and write XML and HTML files. A remote attacker couldprovide a specially crafted XML file that, when processed by an applicationusing libxml2, would lead to excessive CPU consumption (denial of service)based on excessive entity substitutions, even if entity substitution wasdisabled, which is the parser default behavior. (CVE-2014-3660)All libxml2 users are advised to upgrade to these updated packages, whichcontain a backported patch to correct this issue. The desktop must berestarted (log out, then log back in) for this update to take effect.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1655-CentOS 6
CESA-2014:1655-CentOS 7
CVE-2014-3660
RHSA-2014:1655-00
Platform(s):CentOS Linux 6
CentOS Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Product(s):libxml2
Definition Synopsis
  • Red Hat Enterprise Linux 6 and CentOS Linux 6 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages match section
  • libxml2 is earlier than 0:2.7.6-17.el6_6.1
  • OR libxml2-devel is earlier than 0:2.7.6-17.el6_6.1
  • OR libxml2-python is earlier than 0:2.7.6-17.el6_6.1
  • OR libxml2-static is earlier than 0:2.7.6-17.el6_6.1
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND libxml2-debuginfo is earlier than 0:2.7.6-17.el6_6.1
  • Red Hat Enterprise Linux 7 and CentOS Linux 7 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • OR The operating system installed on the system is CentOS Linux 7.x
  • AND Packages match section
  • libxml2 is earlier than 0:2.9.1-5.el7_0.1
  • OR libxml2-devel is earlier than 0:2.9.1-5.el7_0.1
  • OR libxml2-python is earlier than 0:2.9.1-5.el7_0.1
  • OR libxml2-static is earlier than 0:2.9.1-5.el7_0.1
  • Red Hat Enterprise Linux 7 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • AND libxml2-debuginfo is earlier than 0:2.9.1-5.el7_0.1
  • BACK