|
Libxml2 Remote URI Parsing Buffer Overrun Vulnerability
Solution: This issue has been addressed in Libxml2 2.6.6. Turbolinux have released a security advisory (TLSA-2004-12), and updates to address this issue in Turbolinux products. Users are advised to apply these updates as soon as possible, further details regarding obtaining and installing these updates can be found in the referenced advisory. Apple has released a security update (2004-04-05) for Mac OSX/OSX Server versions 10.3.3. Customers are advised to apply this update as soon as possible. Update is linked below. Debian has released an advisory (DSA 455-1) to address this issue in Debian Linux. Please see the referenced advisory for more information. RedHat has released an advisory FEDORA-2004-087 to address this issue in RedHat Fedora. Please see the referenced advisory for more information. RedHat has released an advisory RHSA-2004:090-06 to address this issue. Please see web references for more information. RedHat has released updated advisory RHSA-2004:091-02 to address this issue. Please see the referenced advisory for more information. SGI has released an advisory 20040301-01-U with fixes to address this and other issues. Please see the referenced advisory for more information. Mandrake has released advisory MDKSA-2004:018 to address this issue. Netwosix Linux has released security advisory #2004-0004 dealing with this issue. Fixes are available via the vendor website, please see the reference section for more information and details on obtaining them. OpenPKG has released advisory OpenPKG-SA-2004.003 to address this issue. Trustix released a security advisory that includes updates to address this issue. Gentoo has released advisory GLSA 200403-01 to address this issue. Fixes may be applied with the following commands: emerge sync emerge -pv ">=dev-libs/libxml2-2.6.6" emerge ">=dev-libs/libxml2-2.6.6" Conectiva has released an advisory and fixes dealing with this issue for its Enterprise Linux distribution. Conectiva Linux has released advisory CLA-2004:836 and fixes dealing with this issue. The Fedora legacy advisory (FLSA:1324) has been updated to include python 2.2 support. This advisory address this issue for Red Hat Linux 7.3 running on the i386 platform. Please see the updated advisory for more information. Red Hat has released advisory RHSA-2004:650-03 to address this issue in Red Hat Enterprise Linux. Please see the advisory in Web references for more information. SuSE Linux has released a summary report (SUSE-SR:2005:001) advising that this as well as other issues have been resolved. Please see the referenced advisory for more information. SGI has released advisory 20050101-01-U to address various issues in SGI Advanced Linux Environment 3. This advisory includes updated SGI ProPack 3 Service Pack 3 packages. Please see the referenced advisory for more information. RedHat Linux has released advisory RHSA-2004:650-08 to address this, and other issues for RedHat Enterprise Linux, Desktop Linux and Advanced Workstation for the Itanium Processor. Please see the referenced advisory for further information. SGI has released advisory 20050602-01-U to address this, and other issues for SGI Advanced Linux Environment 3, and SGI ProPack 3 Service Pack 5. Please see the referenced advisory for further information. Fixes are available: XMLSoft Libxml 1.8.17
Turbolinux Turbolinux Desktop 10.0
Apple Mac OS X 10.3.3
Apple Mac OS X Server 10.3.3
SGI ProPack 2.3
SGI ProPack 2.4
XMLSoft Libxml2 2.4.12
XMLSoft Libxml2 2.4.19
XMLSoft Libxml2 2.4.23
XMLSoft Libxml2 2.5.1
XMLSoft Libxml2 2.5.10
XMLSoft Libxml2 2.5.11
XMLSoft Libxml2 2.5.4
XMLSoft Libxml2 2.5.8
XMLSoft Libxml2 2.6 .0
XMLSoft Libxml2 2.6.1
XMLSoft Libxml2 2.6.2
XMLSoft Libxml2 2.6.3
XMLSoft Libxml2 2.6.4
XMLSoft Libxml2 2.6.5
SGI ProPack 3.0
Turbolinux Turbolinux Server 7.0
Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Workstation 8.0
Turbolinux Turbolinux Server 8.0
|
|
|
Privacy Statement |