|
|
Log in / Subscribe / Register

Mageia alert MGASA-2015-0199 (perl-XML-LibXML)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2015-0199: Updated perl-XML-LibXML packages fix CVE-2015-3451
Date:  Wed, 6 May 2015 19:11:09 +0200
Message-ID:  <20150506171109.A40B841E35@valstar.mageia.org>

MGASA-2015-0199 - Updated perl-XML-LibXML packages fix CVE-2015-3451 Publication date: 06 May 2015 URL: http://advisories.mageia.org/MGASA-2015-0199.html Type: security Affected Mageia releases: 4 CVE: CVE-2015-3451 Description: Updated perl-XML-LibXML package fixes security vulnerability: Tilmann Haak from xing.com discovered that XML::LibXML did not respect the expand_entities parameter to disable processing of external entities in some circumstances. This may allow attackers to gain read access to otherwise protected ressources, depending on how the library is used (CVE-2015-3451). References: - https://bugs.mageia.org/show_bug.cgi?id=15803 - https://www.debian.org/security/2015/dsa-3243 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3451 SRPMS: - 4/core/perl-XML-LibXML-2.10.0-2.1.mga4


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds