LWN.net Logo

libxml2: denial of service

Package(s):libxml2 CVE #(s):CVE-2008-4409
Created:October 16, 2008 Updated:December 2, 2008
Description: libxml2 has a denial of service vulnerability. From the Mandriva alert:

libxml2 version 2.7.0 and 2.7.1 did not properly handle predefined entities definitions in entities, which allowed context-dependent attackers to cause a denial of service (memory consumption and application crash) via certain XML documents (CVE-2008-4409).

Alerts:
Gentoo 200812-06 2008-12-02
Mandriva MDVSA-2008:212 2008-10-15

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds