USN-3504-1: libxml2 vulnerability
Wei Lei discovered that libxml2 incorrecty handled certain parameter entities. An attacker could use this issue with specially constructed XML data to cause libxml2 to consume resources, leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability in USN-3504-1?
USN-3504-1 is a vulnerability in libxml2 that allows an attacker to consume resources and cause a denial of service through specially constructed XML data.
Which versions of libxml2 are affected by USN-3504-1?
Versions 2.9.4+dfsg1-4ubuntu1.1, 2.9.4+dfsg1-2.2ubuntu0.2, 2.9.3+dfsg1-1ubuntu0.4, and 2.9.1+dfsg1-3ubuntu4.11 of libxml2 are affected by USN-3504-1.
How can an attacker exploit USN-3504-1?
An attacker can exploit USN-3504-1 by sending specially crafted XML data to the vulnerable system.
What is the remedy for USN-3504-1?
The remedy for USN-3504-1 is to update libxml2 to version 2.9.4+dfsg1-4ubuntu1.1 or later.
Where can I find more information about USN-3504-1?
You can find more information about USN-3504-1 at the following references: [link1] [link2] [link3].