Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes Libxml2 Denial of Service Vulnerability

Title : Fedora Security Update Fixes Libxml2 Denial of Service Vulnerability
VUPEN ID : VUPEN/ADV-2008-0137
CVE ID : CVE-2007-6284
Rated as : Low Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2008-01-14


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format  Receive VUPEN Security notifications by SMS 

A vulnerability has been identified in Fedora, which could be exploited by attackers to cause a denial of service. This issue is caused by an error in Libxml2. For additional information, see : VUPEN/ADV-2008-0117

Affected Products

Fedora 7
Fedora 8

Solution

Upgrade the affected packages :

d9465595b4865fa5109cf1e56679050bb4e867c4 libxml2-debuginfo-2.6.31-1.fc7.ppc64.rpm
cf3134451d1fbcf5e7fe58a4b1435830f058fa07 libxml2-python-2.6.31-1.fc7.ppc64.rpm
b7d41b97ec2692485688c32f01f15da49cef44bd libxml2-devel-2.6.31-1.fc7.ppc64.rpm
86d74adf7c3130b58d13d21f1e1864e5c8fc888f libxml2-2.6.31-1.fc7.ppc64.rpm
fb9492389435fd667e7e9955100856f064e1e908 libxml2-debuginfo-2.6.31-1.fc7.i386.rpm
78f54bdad22cb0f8b647580a0e4757c29f340317 libxml2-python-2.6.31-1.fc7.i386.rpm
3990e9a012df128eec7d56868538d2c607f8c6e6 libxml2-devel-2.6.31-1.fc7.i386.rpm
aeed2d2d5a5daa84bce676b7dbd3ea545c88b5e1 libxml2-2.6.31-1.fc7.i386.rpm
6319d52cc9a04cd380e4b77a3bfdf5f0fb5ded99 libxml2-debuginfo-2.6.31-1.fc7.x86_64.rpm
246a96e4654d9ff64c236de225b53fcf73296ede libxml2-python-2.6.31-1.fc7.x86_64.rpm
8dcbf1fa1eb5e154bddca1583a7f0cb5dbe11fed libxml2-devel-2.6.31-1.fc7.x86_64.rpm
76dcbab6298d29fd8ac384b8bd55ceba89ce75b2 libxml2-2.6.31-1.fc7.x86_64.rpm
8bbdecad4989d856ce76ffd0cc3940eb6a7058ac libxml2-debuginfo-2.6.31-1.fc7.ppc.rpm
37a828af14cabacaa77a690a4032eb30b9445f10 libxml2-python-2.6.31-1.fc7.ppc.rpm
ec9714588eedd274713630d4feac5c157e79e25e libxml2-devel-2.6.31-1.fc7.ppc.rpm
e8d78709e46724424b76809e8e1e3c18d1f10f38 libxml2-2.6.31-1.fc7.ppc.rpm
e18fe16d58b0bef4e63a40cc4d68f12247797932 libxml2-2.6.31-1.fc7.src.rpm

14ef5a9b22f253d602ecad6e18aab5fa6f7c001b libxml2-debuginfo-2.6.31-1.fc8.ppc64.rpm
6b29be9e824206d11399e8f9b6930528f79e70e2 libxml2-python-2.6.31-1.fc8.ppc64.rpm
7c922eb24c4d6acff23d43a393dbf890b51d2278 libxml2-devel-2.6.31-1.fc8.ppc64.rpm
1ec9f2e3e7243eae9f9c775ac64c22e90b8f8819 libxml2-2.6.31-1.fc8.ppc64.rpm
dc44788ae761e342cc8a1c5247a47f064a09e139 libxml2-python-2.6.31-1.fc8.i386.rpm
cb26ffccdea107e3032a1c33eddea24a9a194c5d libxml2-2.6.31-1.fc8.i386.rpm
af00df6bc0eab70326bea298761eaf0cda2dd103 libxml2-debuginfo-2.6.31-1.fc8.i386.rpm
9fb682fbd4cd3dfea253ec7a3d5e53d6ceec1979 libxml2-devel-2.6.31-1.fc8.i386.rpm
4c07f95dc42e480156e64f9b18329d9cae519cce libxml2-debuginfo-2.6.31-1.fc8.x86_64.rpm
3136beb9b3ac26bee6e147fc9f14212838313aec libxml2-python-2.6.31-1.fc8.x86_64.rpm
7dcccaab4e3b01a296109ee58143c8e669f4a1dc libxml2-devel-2.6.31-1.fc8.x86_64.rpm
11d6ad1d5ba49fd23d8ddf8ff59cb95904f3a5a8 libxml2-2.6.31-1.fc8.x86_64.rpm
73c47f66694054436f9cec3a28033c316a19b7b9 libxml2-debuginfo-2.6.31-1.fc8.ppc.rpm
63df7b2c7e5c03da23670660af897c11220394fb libxml2-python-2.6.31-1.fc8.ppc.rpm
96a7875229c90ea5b0dc3d6d304517ca80694917 libxml2-devel-2.6.31-1.fc8.ppc.rpm
082fb8aaf87475cdce1aa3751325fb33ab496798 libxml2-2.6.31-1.fc8.ppc.rpm
244f22ddcd9d82516bdebb544b2270f78ce74e08 libxml2-2.6.31-1.fc8.src.rpm

References

http://www.vupen.com/english/advisories/2008/0137
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00396.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00379.html

ChangeLog

2008-01-14 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7


  >> 2009-05-12

     

  Microsoft Patched 14
  Office PowerPoint Flaws

 

  >> 2009-04-28

     

  Adobe Reader / Acrobat
  Vulnerabilities
Disclosed

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy