Description: | The libxml2 library is a development toolbox providing the implementationof various XML standards.A denial of service flaw was found in libxml2, a library providing supportto read, modify and write XML and HTML files. A remote attacker couldprovide a specially crafted XML file that, when processed by an applicationusing libxml2, would lead to excessive CPU consumption (denial of service)based on excessive entity substitutions, even if entity substitution wasdisabled, which is the parser default behavior. (CVE-2014-3660)All libxml2 users are advised to upgrade to these updated packages, whichcontain a backported patch to correct this issue. The desktop must berestarted (log out, then log back in) for this update to take effect. |