USN-640-1: libxml2 vulnerability
3 September 2008
libxml2 vulnerability
Releases
Packages
- libxml2 -
Details
Andreas Solberg discovered that libxml2 did not handle recursive entities
safely. If an application linked against libxml2 were made to process
a specially crafted XML document, a remote attacker could exhaust the
system's CPU resources, leading to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 8.04
Ubuntu 7.10
Ubuntu 7.04
Ubuntu 6.06
In general, a standard system upgrade is sufficient to effect the
necessary changes.
References
Related notices
- USN-644-1: libxml2