Security update for libxml2
This update for libxml2 fixes the following issues: Security issues fixed: - CVE-2017-9050: heap-based buffer overflow (xmlDictAddString func) [bsc#1039069, bsc#1039661] - CVE-2017-9049: heap-based buffer overflow (xmlDictComputeFastKey func) [bsc#1039066] - CVE-2017-9048: stack overflow vulnerability (xmlSnprintfElementContent func) [bsc#1039063] - CVE-2017-9047: stack overflow vulnerability (xmlSnprintfElementContent func) [bsc#1039064] A clarification for the previously released update: For CVE-2016-9318 we decided not to ship a fix since it can break existing setups. Please take appropriate actions if you parse untrusted XML files and use the new -noxxe flag if possible (bnc#1010675, bnc#1013930).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libxml2 fixes the following issues: Security issues fixed: - CVE-2017-9050: heap-based buffer overflow (xmlDictAddString func) [bsc#1039069, bsc#1039661] - CVE-2017-9049: heap-based buffer overflow (xmlDictComputeFastKey func) [bsc#1039066] - CVE-2017-9048: stack overflow vulnerability (xmlSnprintfElementContent func) [bsc#1039063] - CVE-2017-9047: stack overflow vulnerability (xmlSnprintfElementContent func) [bsc#1039064] A clarification for the previously released update: For CVE-2016-9318 we decided not to ship a fix since it can break existing setups. Please take appropriate actions if you parse untrusted XML files and use the new -noxxe flag if possible (bnc#1010675, bnc#1013930).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1010675
- https://bugzilla.suse.com/1013930
- https://bugzilla.suse.com/1039063
- https://bugzilla.suse.com/1039064
- https://bugzilla.suse.com/1039066
- https://bugzilla.suse.com/1039069
- https://bugzilla.suse.com/1039661
- https://www.suse.com/security/cve/CVE-2016-9318
- https://www.suse.com/security/cve/CVE-2017-9047
- https://www.suse.com/security/cve/CVE-2017-9048
- https://www.suse.com/security/cve/CVE-2017-9049
- https://www.suse.com/security/cve/CVE-2017-9050
- https://www.suse.com/support/update/announcement/2017/suse-su-20171557-1/