libxml2-2.7.6-17.1.0.1.AXS4
エラータID: AXSA:2014-724:04
リリース日:
2014/11/11 Tuesday - 18:22
題名:
libxml2-2.7.6-17.1.0.1.AXS4
影響のあるチャネル:
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- 現時点では CVE-2014-3660 の情報が公開されておりません。
CVE の情報が公開され次第情報をアップデートいたします。
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2014-3660
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
追加情報:
N/A
ダウンロード:
SRPMS
- libxml2-2.7.6-17.1.0.1.AXS4.src.rpm
MD5: f2f32d60c506a3b26ff25d191ff71ad8
SHA-256: 75a6dd6f7a1147f4140f62452c8f088bd23b0ea06a5143f398d73dc89541f403
Size: 4.67 MB
Asianux Server 4 for x86
- libxml2-2.7.6-17.1.0.1.AXS4.i686.rpm
MD5: 28be85c0cb257fcf8406f3c236b90f8b
SHA-256: 33c2e67ef911170dabf626d27b65b1f9c161d45e636c191e72541cdfbee639f1
Size: 800.50 kB - libxml2-devel-2.7.6-17.1.0.1.AXS4.i686.rpm
MD5: 96c7d594eb2b9a8b8a7a36c1790854a9
SHA-256: e5b998323009ab42ed39e37fb19ee1ecd3a5338fa464b29eaf6e7c0c5d56efcb
Size: 1.06 MB - libxml2-python-2.7.6-17.1.0.1.AXS4.i686.rpm
MD5: d1b821ae67e6d33b8a1d3fc80b3bc804
SHA-256: b90cb5c78d5a527dbf4b75357872ebda8e45e416397e23bd9f8e56cfd45ed995
Size: 314.48 kB
Asianux Server 4 for x86_64
- libxml2-2.7.6-17.1.0.1.AXS4.x86_64.rpm
MD5: 61daca3a16186f02063aefd095447c74
SHA-256: e67845b062ba295ad0dde257d74f8dd8014a807a6000c090f70e86d1b3fee40a
Size: 799.82 kB - libxml2-devel-2.7.6-17.1.0.1.AXS4.x86_64.rpm
MD5: 231ad39d808e9f68784ced2c6903eda5
SHA-256: 32b5fb4c72c74fdc78e9c3a76b8efcc529270257f34603b8ffb14266d33c56c5
Size: 1.06 MB - libxml2-python-2.7.6-17.1.0.1.AXS4.x86_64.rpm
MD5: cc71b967753e7d8d766b6b17217552b9
SHA-256: faaeb90de760931a8a23898c258d3d48d564286029918065ae5f61765b2696e3
Size: 320.95 kB - libxml2-2.7.6-17.1.0.1.AXS4.i686.rpm
MD5: 28be85c0cb257fcf8406f3c236b90f8b
SHA-256: 33c2e67ef911170dabf626d27b65b1f9c161d45e636c191e72541cdfbee639f1
Size: 800.50 kB - libxml2-devel-2.7.6-17.1.0.1.AXS4.i686.rpm
MD5: 96c7d594eb2b9a8b8a7a36c1790854a9
SHA-256: e5b998323009ab42ed39e37fb19ee1ecd3a5338fa464b29eaf6e7c0c5d56efcb
Size: 1.06 MB