First published: Wed May 04 2016(Updated: )
A vulnerability was found in libxml2. Parsing a maliciously crafted xml file could cause the application to crash if recover mode is used. References: <a href="http://seclists.org/oss-sec/2016/q2/195">http://seclists.org/oss-sec/2016/q2/195</a>
Affected Software | Affected Version | How to fix |
---|---|---|
libxml2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1332820 is classified as critical due to the potential for application crashes when parsing malicious XML files.
To fix REDHAT-BUG-1332820, update the libxml2 package to the latest version that addresses this vulnerability.
Users of the libxml2 library, particularly those using it in applications with recover mode enabled, are affected by REDHAT-BUG-1332820.
The issue in REDHAT-BUG-1332820 is caused by processing a specially crafted XML file that may lead to a crash when recover mode is employed.
As a workaround for REDHAT-BUG-1332820, avoid using recover mode when parsing XML files unless the library has been updated.