First published: Tue Dec 05 2017(Updated: )
Wei Lei discovered that libxml2 incorrecty handled certain parameter entities. An attacker could use this issue with specially constructed XML data to cause libxml2 to consume resources, leading to a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libxml2 | <2.9.4+dfsg1-4ubuntu1.1 | 2.9.4+dfsg1-4ubuntu1.1 |
=17.10 | ||
All of | ||
ubuntu/libxml2-utils | <2.9.4+dfsg1-4ubuntu1.1 | 2.9.4+dfsg1-4ubuntu1.1 |
=17.10 | ||
All of | ||
ubuntu/python-libxml2 | <2.9.4+dfsg1-4ubuntu1.1 | 2.9.4+dfsg1-4ubuntu1.1 |
=17.10 | ||
All of | ||
ubuntu/python3-libxml2 | <2.9.4+dfsg1-4ubuntu1.1 | 2.9.4+dfsg1-4ubuntu1.1 |
=17.10 | ||
All of | ||
ubuntu/libxml2 | <2.9.4+dfsg1-2.2ubuntu0.2 | 2.9.4+dfsg1-2.2ubuntu0.2 |
=17.04 | ||
All of | ||
ubuntu/libxml2-utils | <2.9.4+dfsg1-2.2ubuntu0.2 | 2.9.4+dfsg1-2.2ubuntu0.2 |
=17.04 | ||
All of | ||
ubuntu/python-libxml2 | <2.9.4+dfsg1-2.2ubuntu0.2 | 2.9.4+dfsg1-2.2ubuntu0.2 |
=17.04 | ||
All of | ||
ubuntu/python3-libxml2 | <2.9.4+dfsg1-2.2ubuntu0.2 | 2.9.4+dfsg1-2.2ubuntu0.2 |
=17.04 | ||
All of | ||
ubuntu/libxml2 | <2.9.3+dfsg1-1ubuntu0.4 | 2.9.3+dfsg1-1ubuntu0.4 |
=16.04 | ||
All of | ||
ubuntu/libxml2-utils | <2.9.3+dfsg1-1ubuntu0.4 | 2.9.3+dfsg1-1ubuntu0.4 |
=16.04 | ||
All of | ||
ubuntu/python-libxml2 | <2.9.3+dfsg1-1ubuntu0.4 | 2.9.3+dfsg1-1ubuntu0.4 |
=16.04 | ||
All of | ||
ubuntu/libxml2 | <2.9.1+dfsg1-3ubuntu4.11 | 2.9.1+dfsg1-3ubuntu4.11 |
=14.04 | ||
All of | ||
ubuntu/libxml2-utils | <2.9.1+dfsg1-3ubuntu4.11 | 2.9.1+dfsg1-3ubuntu4.11 |
=14.04 | ||
All of | ||
ubuntu/python-libxml2 | <2.9.1+dfsg1-3ubuntu4.11 | 2.9.1+dfsg1-3ubuntu4.11 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-3504-1 is a vulnerability in libxml2 that allows an attacker to consume resources and cause a denial of service through specially constructed XML data.
Versions 2.9.4+dfsg1-4ubuntu1.1, 2.9.4+dfsg1-2.2ubuntu0.2, 2.9.3+dfsg1-1ubuntu0.4, and 2.9.1+dfsg1-3ubuntu4.11 of libxml2 are affected by USN-3504-1.
An attacker can exploit USN-3504-1 by sending specially crafted XML data to the vulnerable system.
The remedy for USN-3504-1 is to update libxml2 to version 2.9.4+dfsg1-4ubuntu1.1 or later.
You can find more information about USN-3504-1 at the following references: [link1] [link2] [link3].