RHSA-2008:0886: Important: libxml2 security update
The libxml2 packages provide a library that allows you to manipulate XMLfiles. It includes support to read, modify, and write XML and HTML files.A heap-based buffer overflow flaw was found in the way libxml2 handled longXML entity names. If an application linked against libxml2 processeduntrusted malformed XML content, it could cause the application to crashor, possibly, execute arbitrary code. (CVE-2008-3529)A denial of service flaw was found in the way libxml2 processed certaincontent. If an application linked against libxml2 processed malformed XMLcontent, it could cause the application to use an excessive amount of CPUtime and memory, and stop responding. (CVE-2003-1564)All users of libxml2 are advised to upgrade to these updated packages,which contain backported patches to resolve these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0886?
The severity of RHSA-2008:0886 is classified as important.
How do I fix RHSA-2008:0886?
To fix RHSA-2008:0886, you should update the libxml2 package to the latest version.
What applications are affected by RHSA-2008:0886?
Applications that link against the libxml2 library may be affected by RHSA-2008:0886.
What type of vulnerability is described in RHSA-2008:0886?
RHSA-2008:0886 describes a heap-based buffer overflow flaw in the libxml2 library.
Is there a CVE associated with RHSA-2008:0886?
Yes, RHSA-2008:0886 is associated with multiple CVEs related to buffer overflow vulnerabilities.