REDHAT-BUG-915149: Medium severity libxml2 vulnerability
A denial of service flaw was found in the way libxml2, a library providing support to read, modify and write XML and HTML files, performed string substitutions when entity values for external entity references replacement (--noent option) was requested / enabled during the XML file parsing. A remote attacker could provide a specially-crafted XML file containing an external entity expansion, when processed would lead to excessive CPU consumption (denial of service).
This a different flaw from CVE-2013-0338.
Upstream patch:
http://git.gnome.org/browse/libxml2/commit/?id=23f05e0c33987d6605387b300c4be5da2120a7ab
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-915149?
The severity of REDHAT-BUG-915149 is considered high due to its potential to cause denial of service.
How do I fix REDHAT-BUG-915149?
To fix REDHAT-BUG-915149, update the libxml2 library to the latest version provided by your distribution.
What causes REDHAT-BUG-915149?
REDHAT-BUG-915149 is caused by improper handling of string substitutions during XML parsing with external entity references.
Who is affected by REDHAT-BUG-915149?
Users of the libxml2 library, particularly those using its XML parsing with the --noent option, are affected by REDHAT-BUG-915149.
Is REDHAT-BUG-915149 publicly known?
Yes, REDHAT-BUG-915149 has been publicly disclosed and documented in security databases.