libxml2-2.9.1-6.0.1.el7.AXS7.3
エラータID: AXSA:2016-545:01
This library allows to manipulate XML files. It includes support
to read, modify and write XML and HTML files. There is DTDs support
this includes parsing and validation even with complex DtDs, either
at parse time or later once the document has been modified. The output
can be a simple SAX stream or and in-memory DOM like representations.
In this case one can use the built-in XPath and XPointer implementation
to select sub nodes or ranges. A flexible Input/Output mechanism is
available, with existing HTTP and FTP modules and combined to an
URI library.
Security issues fixed with this release:
CVE-2016-1762
libxml2 in Apple iOS before 9.3, OS X before 10.11.4, Safari before
9.1, tvOS before 9.2, and watchOS before 2.2 allows remote attackers
to execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document.
CVE-2016-1833
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1834, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1834
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1835
libxml2, as used in Apple iOS before 9.3.2 and OS X before 10.11.5,
allows remote attackers to execute arbitrary code or cause a denial of
service (memory corruption) via a crafted XML document.
CVE-2016-1836
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1837, CVE-2016-1838,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1837
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1838,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1838
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837,
CVE-2016-1839, and CVE-2016-1840.
CVE-2016-1839
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837,
CVE-2016-1838, and CVE-2016-1840.
CVE-2016-1840
libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
before 9.2.1, and watchOS before 2.2.1, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted XML document, a different vulnerability than
CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837,
CVE-2016-1838, and CVE-2016-1839.
CVE-2016-3627
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and
earlier, when used in recovery mode, allows context-dependent
attackers to cause a denial of service (infinite recursion, stack
consumption, and application crash) via a crafted XML document.
CVE-2016-3705
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions
in parser.c in libxml2 2.9.3 do not properly keep track of the
recursion depth, which allows context-dependent attackers to cause a
denial of service (stack consumption and application crash) via a
crafted XML document containing a large number of nested entity
references.
CVE-2016-4447
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4
allows context-dependent attackers to cause a denial of service
(heap-based buffer underread and application crash) via a crafted
file, involving xmlParseName.
CVE-2016-4448
Format string vulnerability in libxml2 before 2.9.4 allows attackers
to have unspecified impact via format string specifiers in unknown
vectors.
CVE-2016-4449
XML external entity (XXE) vulnerability in the
xmlStringLenDecodeEntities function in parser.c in libxml2 before
2.9.4, when not in validating mode, allows context-dependent attackers
to read arbitrary files or cause a denial of service (resource
consumption) via unspecified vectors.
Update packages.
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of service via a crafted XML document.
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document.
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
N/A
SRPMS
- libxml2-2.9.1-6.0.1.el7.AXS7.3.src.rpm
MD5: 73e27cb68efd556fb96835c8419f657a
SHA-256: 7ffb5f34a7da254bf21969346cf56bb3a5fdb544f5ffda3fa0daa9c81cd7ab7e
Size: 5.02 MB
Asianux Server 7 for x86_64
- libxml2-2.9.1-6.0.1.el7.AXS7.3.x86_64.rpm
MD5: 094cb467306da87752bc45239cf49d67
SHA-256: 37f8e7e8ba0ecb0fc138efc2e1e9abb581e62aaf5d5a1c596ac264a05c899946
Size: 667.24 kB - libxml2-devel-2.9.1-6.0.1.el7.AXS7.3.x86_64.rpm
MD5: da1e05683b1a90453525f92d981ed73d
SHA-256: a271657ee2cf20dee773020411b6f5717c5bc1787bb660ae3016f0a26420b522
Size: 1.05 MB - libxml2-python-2.9.1-6.0.1.el7.AXS7.3.x86_64.rpm
MD5: 6cb9fd0242109d64badc6c90663edb30
SHA-256: 01e30edf6c2dcfcb0a9bcad473d5db3fd1bdce623a9f0896082bc2d2bff78d64
Size: 245.84 kB - libxml2-2.9.1-6.0.1.el7.AXS7.3.i686.rpm
MD5: fca28ecd452fc82808d467700e0cca8c
SHA-256: e3f65fa9d91dec9dbee5fb0e4dd3374234d01b42c4b351300ef0389379629125
Size: 653.44 kB - libxml2-devel-2.9.1-6.0.1.el7.AXS7.3.i686.rpm
MD5: 65e31c22d3930f73da34bd422b13cf88
SHA-256: 85d37510eee2fc0378120af110aa1932ed915369394295b1c4a9ec7afc23b11e
Size: 1.05 MB