OVMSA-2014-0031

OVMSA-2014-0031 - libxml2 security update

Type:SECURITY
Impact:MODERATE
Release Date:2014-11-03

Description


[2.7.6-17.0.1.el6_6.1]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[libxml2-2.7.6-17.el6.1]
- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149085)

[libxml2-2.7.6-17.el6]
- Fix a set of regressions introduced in CVE-2014-0191 (rhbz#1105011)

[libxml2-2.7.6-16.el6]
- Improve handling of xmlStopParser(CVE-2013-2877)

[libxml2-2.7.6-15.el6]
- Do not fetch external parameter entities (CVE-2014-0191)

[libxml2-2.7.6-14.el6]
- Fix a regression in 2.9.0 breaking validation while streaming (rhbz#863166)

[2.7.6-13.el6]
- detect and stop excessive entities expansion upon replacement (rhbz#912575)


Related CVEs


CVE-2014-3660

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle VM 3.3 (x86_64) libxml2-2.7.6-17.0.1.el6_6.1.src.rpm5147ff6e22185b1f1144cd9a66f6bab41977a33ffc3159255a1178eea0143507OVMSA-2016-0087ovm3_x86_64_3.3_patch
libxml2-2.7.6-17.0.1.el6_6.1.x86_64.rpmd59535a8c1fcaa9ea78fa769a4fd349e82bde7cce4f417de4d5ec485bd43b862OVMSA-2016-0087ovm3_x86_64_3.3_patch
libxml2-python-2.7.6-17.0.1.el6_6.1.x86_64.rpm8d147b99d474fda118200765a502a00cbbcbcdd9337072b26e68fd5cd2da1304OVMSA-2016-0087ovm3_x86_64_3.3_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete