FlawAtlas
Search the atlas
SUSE-SU-2017:0164-1 Not scored

Security update for libxml2

This update for libxml2 fixes the following issues: * CVE-2016-9318: libxml2 did not offer a flag directly indicating that the current document may be read but other files may not be opened, which made it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document (bsc#1010675). * Prevent NULL dereference in xpointer.c and xmlDumpElementContent, and infinite recursion in xmlParseConditionalSections when in recovery mode(bnc#1014873)

Exploit probability Not scored
Published January 16, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 11 SP4 libxml2
SUSE:Linux Enterprise Server 11 SP4 libxml2-python
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 libxml2
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 libxml2-python
SUSE:Linux Enterprise Software Development Kit 11 SP4 libxml2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2017:0164-1

This update for libxml2 fixes the following issues: * CVE-2016-9318: libxml2 did not offer a flag directly indicating that the current document may be read but other files may not be opened, which made it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document (bsc#1010675). * Prevent NULL dereference in xpointer.c and xmlDumpElementContent, and infinite recursion in xmlParseConditionalSections when in recovery mode(bnc#1014873)

View original source

05 / REFERENCES

Further evidence