Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.851341
Categoría:SuSE Local Security Checks
Título:openSUSE: Security Advisory for libxml2 (openSUSE-SU-2016:1595-1)
Resumen:The remote host is missing an update for the 'libxml2'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'libxml2'
package(s) announced via the referenced advisory.

Vulnerability Insight:
This update for libxml2 fixes the following security issues:

- CVE-2016-2073, CVE-2015-8806, CVE-2016-1839: A Heap-buffer overread was
fixed in libxml2/dict.c [bsc#963963, bsc#965283, bsc#981114].

- CVE-2016-4483: Code was added to avoid an out of bound access when
serializing malformed strings [bsc#978395].

- CVE-2016-1762: Fixed a heap-based buffer overread in xmlNextChar
[bsc#981040].

- CVE-2016-1834: Fixed a heap-buffer-overflow in xmlStrncat [bsc#981041].

- CVE-2016-1833: Fixed a heap-based buffer overread in htmlCurrentChar
[bsc#981108].

- CVE-2016-1835: Fixed a heap use-after-free in xmlSAX2AttributeNs
[bsc#981109].

- CVE-2016-1837: Fixed a heap use-after-free in htmlParsePubidLiteral and
htmlParseSystemiteral [bsc#981111].

- CVE-2016-1838: Fixed a heap-based buffer overread in
xmlParserPrintFileContextInternal [bsc#981112].

- CVE-2016-1840: Fixed a heap-buffer-overflow in xmlFAParsePosCharGroup
[bsc#981115].

- CVE-2016-4447: Fixed a heap-based buffer-underreads due to xmlParseName
[bsc#981548].

- CVE-2016-4448: Fixed some format string warnings with possible format
string vulnerability [bsc#981549],

- CVE-2016-4449: Fixed inappropriate fetch of entities content
[bsc#981550].

- CVE-2016-3705: Fixed missing increment of recursion counter.

This update was imported from the SUSE:SLE-12:Update update project.

Affected Software/OS:
libxml2 on openSUSE Leap 42.1

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-8806
BugTraq ID: 82071
http://www.securityfocus.com/bid/82071
Debian Security Information: DSA-3593 (Google Search)
https://www.debian.org/security/2016/dsa-3593
https://security.gentoo.org/glsa/201701-37
https://bugzilla.gnome.org/show_bug.cgi?id=749115
http://www.openwall.com/lists/oss-security/2016/02/03/5
http://www.ubuntu.com/usn/USN-2994-1
Common Vulnerability Exposure (CVE) ID: CVE-2016-1762
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html
http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html
http://lists.apple.com/archives/security-announce/2016/Mar/msg00002.html
http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html
BugTraq ID: 85059
http://www.securityfocus.com/bid/85059
RedHat Security Advisories: RHSA-2016:1292
https://access.redhat.com/errata/RHSA-2016:1292
RedHat Security Advisories: RHSA-2016:2957
http://rhn.redhat.com/errata/RHSA-2016-2957.html
http://www.securitytracker.com/id/1035353
Common Vulnerability Exposure (CVE) ID: CVE-2016-1833
http://lists.apple.com/archives/security-announce/2016/May/msg00001.html
http://lists.apple.com/archives/security-announce/2016/May/msg00002.html
http://lists.apple.com/archives/security-announce/2016/May/msg00003.html
http://lists.apple.com/archives/security-announce/2016/May/msg00004.html
BugTraq ID: 90691
http://www.securityfocus.com/bid/90691
https://bugs.chromium.org/p/project-zero/issues/detail?id=636
http://www.securitytracker.com/id/1035890
Common Vulnerability Exposure (CVE) ID: CVE-2016-1834
Common Vulnerability Exposure (CVE) ID: CVE-2016-1835
BugTraq ID: 90696
http://www.securityfocus.com/bid/90696
Common Vulnerability Exposure (CVE) ID: CVE-2016-1837
Common Vulnerability Exposure (CVE) ID: CVE-2016-1838
https://bugs.chromium.org/p/project-zero/issues/detail?id=639
Common Vulnerability Exposure (CVE) ID: CVE-2016-1839
http://www.securitytracker.com/id/1038623
Common Vulnerability Exposure (CVE) ID: CVE-2016-1840
Common Vulnerability Exposure (CVE) ID: CVE-2016-2073
BugTraq ID: 85267
http://www.securityfocus.com/bid/85267
http://www.openwall.com/lists/oss-security/2016/01/25/6
http://www.openwall.com/lists/oss-security/2016/01/26/7
http://www.securitytracker.com/id/1035011
Common Vulnerability Exposure (CVE) ID: CVE-2016-3705
BugTraq ID: 89854
http://www.securityfocus.com/bid/89854
http://seclists.org/fulldisclosure/2016/May/10
SuSE Security Announcement: openSUSE-SU-2016:1298 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-05/msg00055.html
SuSE Security Announcement: openSUSE-SU-2016:1446 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-05/msg00127.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-4447
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html
http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.html
http://lists.apple.com/archives/security-announce/2016/Jul/msg00002.html
http://lists.apple.com/archives/security-announce/2016/Jul/msg00003.html
http://lists.apple.com/archives/security-announce/2016/Jul/msg00005.html
BugTraq ID: 90864
http://www.securityfocus.com/bid/90864
http://www.openwall.com/lists/oss-security/2016/05/25/2
http://www.securitytracker.com/id/1036348
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.404722
Common Vulnerability Exposure (CVE) ID: CVE-2016-4448
BugTraq ID: 90856
http://www.securityfocus.com/bid/90856
Common Vulnerability Exposure (CVE) ID: CVE-2016-4449
BugTraq ID: 90865
http://www.securityfocus.com/bid/90865
http://jvn.jp/en/jp/JVN17535578/index.html
http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000066.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-4483
BugTraq ID: 90013
http://www.securityfocus.com/bid/90013
http://www.debian.org/security/2016/dsa-3593
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
http://www.openwall.com/lists/oss-security/2016/05/03/8
http://www.openwall.com/lists/oss-security/2016/05/04/7
http://www.openwall.com/lists/oss-security/2016/06/07/4
http://www.openwall.com/lists/oss-security/2016/06/07/5
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.