First published: Thu Sep 11 2008(Updated: )
The libxml2 packages provide a library that allows you to manipulate XML<br>files. It includes support to read, modify, and write XML and HTML files.<br>A heap-based buffer overflow flaw was found in the way libxml2 handled long<br>XML entity names. If an application linked against libxml2 processed<br>untrusted malformed XML content, it could cause the application to crash<br>or, possibly, execute arbitrary code. (CVE-2008-3529)<br>A denial of service flaw was found in the way libxml2 processed certain<br>content. If an application linked against libxml2 processed malformed XML<br>content, it could cause the application to use an excessive amount of CPU<br>time and memory, and stop responding. (CVE-2003-1564)<br>All users of libxml2 are advised to upgrade to these updated packages,<br>which contain backported patches to resolve these issues.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.