libxml2-2.9.1-6.0.1.el7.AXS7.3

エラータID: AXSA:2016-545:01

Release date: 
Monday, July 11, 2016 - 17:18
Subject: 
libxml2-2.9.1-6.0.1.el7.AXS7.3
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

This library allows to manipulate XML files. It includes support
to read, modify and write XML and HTML files. There is DTDs support
this includes parsing and validation even with complex DtDs, either
at parse time or later once the document has been modified. The output
can be a simple SAX stream or and in-memory DOM like representations.
In this case one can use the built-in XPath and XPointer implementation
to select sub nodes or ranges. A flexible Input/Output mechanism is
available, with existing HTTP and FTP modules and combined to an
URI library.

Security issues fixed with this release:

CVE-2016-1762
libxml2 in Apple iOS before 9.3, OS X before 10.11.4, Safari before
9.1, tvOS before 9.2, and watchOS before 2.2 allows remote attackers
to execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document.
CVE-2016-1833
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1834, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1834
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1835
libxml2, as used in Apple iOS before 9.3.2 and OS X before 10.11.5,
allows remote attackers to execute arbitrary code or cause a denial of
service (memory corruption) via a crafted XML document.
CVE-2016-1836
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1837, CVE-2016-1838,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1837
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1838,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1838
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1839
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837,
CVE-2016-1838, and CVE-2016-1840.
CVE-2016-1840
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837,
CVE-2016-1838, and CVE-2016-1839.
CVE-2016-3627
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and
earlier, when used in recovery mode, allows context-dependent
attackers to cause a denial of service (infinite recursion, stack
consumption, and application crash) via a crafted XML document.
CVE-2016-3705
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions
in parser.c in libxml2 2.9.3 do not properly keep track of the
recursion depth, which allows context-dependent attackers to cause a
denial of service (stack consumption and application crash) via a
crafted XML document containing a large number of nested entity
references.
CVE-2016-4447
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4
allows context-dependent attackers to cause a denial of service
(heap-based buffer underread and application crash) via a crafted
file, involving xmlParseName.
CVE-2016-4448
Format string vulnerability in libxml2 before 2.9.4 allows attackers
to have unspecified impact via format string specifiers in unknown
vectors.
CVE-2016-4449
XML external entity (XXE) vulnerability in the
xmlStringLenDecodeEntities function in parser.c in libxml2 before
2.9.4, when not in validating mode, allows context-dependent attackers
to read arbitrary files or cause a denial of service (resource
consumption) via unspecified vectors.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libxml2-2.9.1-6.0.1.el7.AXS7.3.src.rpm
    MD5: 73e27cb68efd556fb96835c8419f657a
    SHA-256: 7ffb5f34a7da254bf21969346cf56bb3a5fdb544f5ffda3fa0daa9c81cd7ab7e
    Size: 5.02 MB

Asianux Server 7 for x86_64
  1. libxml2-2.9.1-6.0.1.el7.AXS7.3.x86_64.rpm
    MD5: 094cb467306da87752bc45239cf49d67
    SHA-256: 37f8e7e8ba0ecb0fc138efc2e1e9abb581e62aaf5d5a1c596ac264a05c899946
    Size: 667.24 kB
  2. libxml2-devel-2.9.1-6.0.1.el7.AXS7.3.x86_64.rpm
    MD5: da1e05683b1a90453525f92d981ed73d
    SHA-256: a271657ee2cf20dee773020411b6f5717c5bc1787bb660ae3016f0a26420b522
    Size: 1.05 MB
  3. libxml2-python-2.9.1-6.0.1.el7.AXS7.3.x86_64.rpm
    MD5: 6cb9fd0242109d64badc6c90663edb30
    SHA-256: 01e30edf6c2dcfcb0a9bcad473d5db3fd1bdce623a9f0896082bc2d2bff78d64
    Size: 245.84 kB
  4. libxml2-2.9.1-6.0.1.el7.AXS7.3.i686.rpm
    MD5: fca28ecd452fc82808d467700e0cca8c
    SHA-256: e3f65fa9d91dec9dbee5fb0e4dd3374234d01b42c4b351300ef0389379629125
    Size: 653.44 kB
  5. libxml2-devel-2.9.1-6.0.1.el7.AXS7.3.i686.rpm
    MD5: 65e31c22d3930f73da34bd422b13cf88
    SHA-256: 85d37510eee2fc0378120af110aa1932ed915369394295b1c4a9ec7afc23b11e
    Size: 1.05 MB