Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1631-1] New libxml2 packages fix denial of service (1/2

    From Steve Kemp@1:229/2 to All on Fri Aug 22 21:50:09 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1631-1 [email protected] http://www.debian.org/security/ Steve Kemp
    August 22, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : libxml2
    Vulnerability : denial of service
    Problem type : local
    Debian-specific: no
    CVE Id(s) : CVE-2008-3281

    Andreas Solberg discovered that libxml2, the GNOME XML library,
    could be forced to recursively evaluate entities, until available
    CPU & memory resources were exhausted.

    For the stable distribution (etch), this problem has been fixed in version 2.6.27.dfsg-3.

    For the unstable distribution (sid), this problem will be fixed soon.

    We recommend that you upgrade your libxml2 package.


    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg.orig.tar.gz
    Size/MD5 checksum: 3416175 5ff71b22f6253a6dd9afc1c34778dec3
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-3.dsc
    Size/MD5 checksum: 901 800082d165a5627f571f019994bee93c
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-3.diff.gz
    Size/MD5 checksum: 146017 10fc8479d96fb23d17ac8a51bfe40db9

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-doc_2.6.27.dfsg-3_all.deb
    Size/MD5 checksum: 1325318 11e64cd82ae7b549fa975a657f773f73

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-3_alpha.deb
    Size/MD5 checksum: 37976 909bab48a2b4a6c29e11b8b880dd464d
    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-3_alpha.deb
    Size/MD5 checksum: 184758 2dbe0e48211dff90726296ee6786b73b
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-3_alpha.deb
    Size/MD5 checksum: 881704 110adb2bde79f8feb121beaa9ae8e15d
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-3_alpha.deb
    Size/MD5 checksum: 916192 fd97550bc89ee18ef4c58da00b2c8b1c
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-3_alpha.deb
    Size/MD5 checksum: 820740 47ba8095722f2bbdf6e88fa6881b365e

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-3_amd64.deb
    Size/MD5 checksum: 36774 78fbbff7c5a940d516ddab2145af3a04
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-3_amd64.deb
    Size/MD5 checksum: 891114 54574b53e6e1d243c9a3a8db7a7ff845
    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-3_amd64.deb
    Size/MD5 checksum: 182908 28cfebcd7ab010cf63e9261147be9806
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-3_amd64.deb
    Size/MD5 checksum: 746356 96ee63f89da370e08d4d7cf2d656c414
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-3_amd64.deb
    Size/MD5 checksum: 796450 d9e1bc7ac6e9ac08a50e4cc7fd245433

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-3_arm.deb
    Size/MD5 checksum: 672716 21723fdd5875eb16170ec69734fa4cd4
    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-3_arm.deb
    Size/MD5 checksum: 165296 091714fdcb9c7c7909496ac14d9af71d
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-3_arm.deb
    Size/MD5 checksum: 34676 d1acb4cd2a7036e35a7cfbcdc25362b7
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-3_arm.deb
    Size/MD5 checksum: 816944 102757770541cb1d1336bb4d3c086aa8
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-3_arm.deb
    Size/MD5 checksum: 741122 35af939918be6655ca6994462a3b9610

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-3_hppa.deb
    Size/MD5 checksum: 192856 0f670bcbefb06ace1dcd643e4045d5ce
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-3_hppa.deb
    Size/MD5 checksum: 857960 cc1632c8c04e9582e79e46729ce6657b
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-3_hppa.deb
    Size/MD5 checksum: 36856 35450be2eee5c16c4ac8b230b8d67de5
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-3_hppa.deb
    Size/MD5 checksum: 863890 fd6b47e9995c8150fe0d42036de52b92
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-3_hppa.deb
    Size/MD5 checksum: 849758 3199a4ab9ce81877235f78c611f0ae4e

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-3_i386.deb
    Size/MD5 checksum: 857370 6a293fc2b6aeadb289e28a4566fbfc86
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-3_i386.deb
    Size/MD5 checksum: 681830 2117114ebcaa25a76d21c454df990789
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-3_i386.deb
    Size/MD5 checksum: 755986 7291a82a169cd4fa7b0d3347685fb3ad
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-3_i386.deb
    Size/MD5 checksum: 34456 092ad89155004c50686cafca63b9257b
    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-3_i386.deb
    Size/MD5 checksum: 169520 55365fa5e3fe422f0c09492d8289db6b


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Steve Kemp@1:229/2 to All on Tue Aug 26 20:00:12 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1631-2 [email protected] http://www.debian.org/security/ Steve Kemp
    August 26, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : libxml2
    Vulnerability : denial of service
    Problem type : local
    Debian-specific: no
    CVE Id(s) : CVE-2008-3281

    The previous security update of the libxml2 package introduced
    some problems with other packages, most notably with librsvg.
    This update corrects these problems whilst still fixing the
    reported scurity problem.

    For reference the text of the previous security announcement
    follows:

    Andreas Solberg discovered that libxml2, the GNOME XML library,
    could be forced to recursively evaluate entities, until available
    CPU & memory resources were exhausted.

    For the stable distribution (etch), this problem has been fixed in version 2.6.27.dfsg-4.

    For the unstable distribution (sid), this problem has been fixed in
    version 2.6.32.dfsg-3.

    We recommend that you upgrade your libxml2 package.


    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-4.dsc
    Size/MD5 checksum: 893 71d8dbd9fb4d082a273289513941da33
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg.orig.tar.gz
    Size/MD5 checksum: 3416175 5ff71b22f6253a6dd9afc1c34778dec3
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-4.diff.gz
    Size/MD5 checksum: 145887 5579bcc5d4fb2e33789853d826e265a3

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-doc_2.6.27.dfsg-4_all.deb
    Size/MD5 checksum: 1328140 adb1d2d477eacbaf8347aa50eac782bb

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-4_alpha.deb
    Size/MD5 checksum: 820516 31ef1df11042703555ae2be4cd070d77
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-4_alpha.deb
    Size/MD5 checksum: 881632 3ed598806d32756af480a32db50d29bb
    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-4_alpha.deb
    Size/MD5 checksum: 184762 9dcde3e1f90ff7dfc42b2c8ce0c0e24e
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-4_alpha.deb
    Size/MD5 checksum: 916300 ed1c5f1efa3dc141d5d4c79820bfef3c
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-4_alpha.deb
    Size/MD5 checksum: 37978 47fe74c3d93abc8e596d836ef4eb8fcb

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-4_amd64.deb
    Size/MD5 checksum: 184120 58ab6cccdd5484e4bfcf4b6dd27c9e00
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-4_amd64.deb
    Size/MD5 checksum: 36680 dd0b6f7984f011ae92bd7e09bf83f02f
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-4_amd64.deb
    Size/MD5 checksum: 795770 4063d07d3876bfbc3f6fcf19e5cafb4a
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-4_amd64.deb
    Size/MD5 checksum: 891790 b727f5ae98ce30abe97a1fba3ac40d38
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-4_amd64.deb
    Size/MD5 checksum: 745276 5af9ee2e1337339b2e892fedba428e3c

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-4_arm.deb
    Size/MD5 checksum: 165294 ad35b56851b1593e360b686ecfec65fc
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-4_arm.deb
    Size/MD5 checksum: 672778 b08822852ad4599685c9dc3188373c4d
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-4_arm.deb
    Size/MD5 checksum: 741398 47071e65bd39d46da2671a307254ae1e
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-4_arm.deb
    Size/MD5 checksum: 816988 f52a68650d018f67aab33ae26d5dd143
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-4_arm.deb
    Size/MD5 checksum: 34672 a936724e14d1319ca9a79a0f3711d250

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/libx/libxml2/python-libxml2_2.6.27.dfsg-4_hppa.deb
    Size/MD5 checksum: 192854 81a84d2b04ad199969eff68a5132850e
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-utils_2.6.27.dfsg-4_hppa.deb
    Size/MD5 checksum: 36858 2473f5535d88f7f15d5828896384c40a
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-4_hppa.deb
    Size/MD5 checksum: 849856 99c8f064ed4f2eaad000bb5069ef302e
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dbg_2.6.27.dfsg-4_hppa.deb
    Size/MD5 checksum: 863750 e830ea5314f70dee660743fc1c9b158d
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-4_hppa.deb
    Size/MD5 checksum: 858008 4fea504a87f852497df6288315275ccf

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.6.27.dfsg-4_i386.deb
    Size/MD5 checksum: 681202 30924287393f6c3be0cabd7459233384
    http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.6.27.dfsg-4_i386.deb
    Size/MD5 checksum: 755716 8d5a4b27d85883876fb6a801b81e4a22

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 151:29:02
    Calls: 12,091
    Calls today: 4
    Files: 15,000
    Messages: 6,517,607

© >>> Magnum BBS <<<, 2026