• [SECURITY] [DSA 2417-1] libxml2 security update

    From Nico Golde@1:229/2 to All on Thu Feb 23 00:10:02 2012
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2417-1 [email protected] http://www.debian.org/security/ Nico Golde February 22, 2012 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : libxml2
    Vulnerability : computational denial of service
    Problem type : local/remote
    Debian-specific: no
    Debug bug : 660846
    CVE ID : CVE-2012-0841

    It was discovered that the internal hashing routine of libxml2,
    a library providing an extensive API to handle XML data, is vulnerable to predictable hash collisions. Given an attacker with knowledge of the
    hashing algorithm, it is possible to craft input that creates a large
    amount of collisions. As a result it is possible to perform denial of
    service attacks against applications using libxml2 functionality because
    of the computational overhead.


    For the stable distribution (squeeze), this problem has been fixed in
    version 2.7.8.dfsg-2+squeeze3.

    For the testing (wheezy) and unstable (sid) distributions, this problem
    will be fixed soon.

    We recommend that you upgrade your libxml2 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.11 (GNU/Linux)

    iEYEARECAAYFAk9FdM8ACgkQHYflSXNkfP+BkwCcDh11fC0BO+8QLOjCnwYlJ9xt jQwAnjBxzz8GLFVXLMuTTlrV4lnVvD6h
    =0qEK
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)