SUSE-SU-2018:3081-1
Vulnerability Summary
Timeline
Description
Security update for libxml2 This update for libxml2 fixes the following security issues: - CVE-2018-9251: The xz_decomp function allowed remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint (bsc#1088279). - CVE-2018-14567: Prevent denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint (bsc#1105166). - CVE-2018-14404: Prevent NULL pointer dereference in the xmlXPathCompOpEval() function when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case leading to a denial of service attack (bsc#1102046). - CVE-2017-18258: The xz_head function allowed remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality did not restrict memory usage to what is required for a legitimate file (bsc#1088601).
Affected Systems
- suse•libxml2&distro=SUSE Linux Enterprise Desktop 12 SP3
< 2.9.4-46.15.1
- suse•libxml2&distro=SUSE Linux Enterprise Server 12 SP3
< 2.9.4-46.15.1
- suse•libxml2&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP3
< 2.9.4-46.15.1
- suse•libxml2&distro=SUSE Linux Enterprise Software Development Kit 12 SP3
< 2.9.4-46.15.1
- suse•python-libxml2&distro=SUSE Linux Enterprise Desktop 12 SP3
< 2.9.4-46.15.1
- suse•python-libxml2&distro=SUSE Linux Enterprise Server 12 SP3
< 2.9.4-46.15.1
- suse•python-libxml2&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP3
< 2.9.4-46.15.1
References (9)
- https://www.suse.com/support/update/announcement/2018/suse-su-20183081-1/
- https://bugzilla.suse.com/1088279
- https://bugzilla.suse.com/1088601
- https://bugzilla.suse.com/1102046
- https://bugzilla.suse.com/1105166
- https://www.suse.com/security/cve/CVE-2017-18258
- https://www.suse.com/security/cve/CVE-2018-14404
- https://www.suse.com/security/cve/CVE-2018-14567
- https://www.suse.com/security/cve/CVE-2018-9251