Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· System Builder Marathon, Q2 2013 and more
· Microsoft delivers biggest update to date to TypeScript
· Tiff/nss-pam-ldapd Updates for Debian
· Update for Windows 8/Server 2012
· Apple TV 5.4 beta adds iTunes Radio, Conference Room Display
· DSA 2710-1: xml-security-c security update
· Intel DZ87KLT-75K Kinsley Thunderbolt Motherboard Review
· Microsoft launches Surface RT discount for schools
· MacStadium to provide new Mac Pro hosting and colocation
· Netflix outside the USA - in Linux & with Tunlr

Upcoming News
· NZXT Phantom 630 Ultra Tower
· An MTN News Flash - MEGATech Reviews: Wicked Audio EVAC Full-Size Headphones
· [security-announce] openSUSE-SU-2013:1042-1: critical: kernel: security and bugfix update
· [security-announce] openSUSE-SU-2013:1043-1: critical: kernel
· Fractal Design Arc Midi R2 Case Review
· Mad Catz Cyborg F.R.E.Q. 5 Gaming Headset @ Benchmark Reviews
· News: MSI's Z87-GD65 Gaming motherboard reviewed
· OCZ Vertex 450 256GB SSD Review @ Hardware Canucks
· ASUS Z87-PRO Motherboard Review @ HiTech Legion
· REVIEW: Cooler Master Seidon 240M @ PureOverclock

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2635 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3445 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93196 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 179 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6892 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » March 2004 » DSA 455-1: New libxml packages fix arbitrary code execution

DSA 455-1: New libxml packages fix arbitrary code execution

Posted by Philipp Esselbach on: 03/04/2004 06:30 AM [ Print | 0 comment(s) ]

---------------------------------------------------------------------------
Debian Security Advisory DSA 455-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
March 3rd, 2004 http://www.debian.org/security/faq
---------------------------------------------------------------------------

Package : libxml, libxml2
Vulnerability : buffer overflows
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2004-0110

libxml2 is a library for manipulating XML files.

Yuuichi Teranishi discovered a flaw in libxml, the GNOME XML library. When fetching a remote resource via FTP or HTTP, the library uses special parsing routines which can overflow a buffer if passed a very long URL. If an attacker is able to find an application using libxml1 or libxml2 that parses remote resources and allows the attacker to craft the URL, then this flaw could be used to execute arbitrary code.

For the stable distribution (woody) this problem has been fixed in version 1.8.17-2woody1 of libxml and version 2.4.19-4woody1 of libxml2.

For the unstable distribution (sid) this problem has been fixed in version 1.8.17-5 of libxml and version 2.6.6-1 of libxml2.

We recommend that you upgrade your libxml1 and libxml2 packages.




Upgrade Instructions
---------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
---------------------------------

Source archives:

http://security.debian.org/pool/updates/main/libx/libxml/libxml_1.8.17-2woody1.dsc
Size/MD5 checksum: 651 16512f774479d73b7d82ca4e1db527f5
http://security.debian.org/pool/updates/main/libx/libxml/libxml_1.8.17-2woody1.diff.gz
Size/MD5 checksum: 33976 68afef27edf44d2b81e02fde3431bca8
http://security.debian.org/pool/updates/main/libx/libxml/libxml_1.8.17.orig.tar.gz
Size/MD5 checksum: 1016403 b8f01e43e1e03dec37dfd6b4507a9568

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1.dsc
Size/MD5 checksum: 654 6f56380f9bfade2c66f03956e1a65162
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1.diff.gz
Size/MD5 checksum: 344358 ba3ea49cc8c465ff1a6377780c35a45d
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19.orig.tar.gz
Size/MD5 checksum: 1925487 22e3c043f57e18baaed86c5fff3eafbc

Alpha architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_alpha.deb
Size/MD5 checksum: 381994 dc3ada5391f52bdfd642df1bc5b9a6be
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_alpha.deb
Size/MD5 checksum: 208830 a0698c267c722bf5127ee3709024ecc9

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_alpha.deb
Size/MD5 checksum: 388786 a4ece19b65c46dd0e8f889c26e5938b3
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_alpha.deb
Size/MD5 checksum: 938568 5f3e46bd132c9167db9e93ca3c739952

ARM architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_arm.deb
Size/MD5 checksum: 392536 9e126158928d24a562ae1d2b3d35ae1d
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_arm.deb
Size/MD5 checksum: 184172 0527fd6a14e003139be9b475e689ee41

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_arm.deb
Size/MD5 checksum: 346060 6b9caeac9a0061576f8a1e5b46ed8671
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_arm.deb
Size/MD5 checksum: 902966 688fb8c5ea18b0f9d8e7671dad5426c5

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_i386.deb
Size/MD5 checksum: 330042 b1c61849e10edbe597429fcd05d1d2b3
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_i386.deb
Size/MD5 checksum: 183310 3c217f980c138f24eac1a0abd89eba78

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_i386.deb
Size/MD5 checksum: 333034 11cfc7169e549c63dccf28f15300a8eb
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_i386.deb
Size/MD5 checksum: 843084 43a242f53ed8a688e5ed02284a150f52

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_ia64.deb
Size/MD5 checksum: 447184 5bfa2835a9d9b43da6d31e1cadce6bc1
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_ia64.deb
Size/MD5 checksum: 285484 a378583eaaaf1248aba8de4fd721c5fc

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_ia64.deb
Size/MD5 checksum: 507452 b447844080f6e0c1d498b34ec849c9b2
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_ia64.deb
Size/MD5 checksum: 1032662 ddd7aae0835fe1edb04aee7cdf2e41c0

HP Precision architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_hppa.deb
Size/MD5 checksum: 439372 d5f629dc7f885dd858671ab639d954f8
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_hppa.deb
Size/MD5 checksum: 248212 837ec145aac757ce053075a4736ddb55

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_hppa.deb
Size/MD5 checksum: 425454 0719d6e0835b6dae714b1ce1a0bd9d77
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_hppa.deb
Size/MD5 checksum: 979152 41e110f4c9805a5afb94fff79d1f3d22

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_m68k.deb
Size/MD5 checksum: 318176 d0dcb654f8083e0873396d38aaa1a7a2
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_m68k.deb
Size/MD5 checksum: 178226 c18c0c7bb3c0884c62f36922e5843e83

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_m68k.deb
Size/MD5 checksum: 336902 2990a52db32dc3fd3108be4e677e59bf
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_m68k.deb
Size/MD5 checksum: 828820 6378b37494b667bce472f934f50c3cb8

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_mips.deb
Size/MD5 checksum: 376266 1c226409e23047ec521224697a82f76c
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_mips.deb
Size/MD5 checksum: 183628 0fa6098bdbfeadb50dfb7e5f4f2c967c

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_mips.deb
Size/MD5 checksum: 348902 474e9b8bc026ca199218727203422c12
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_mips.deb
Size/MD5 checksum: 921098 b8aa537054fc482ab042647ac0551f94

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_mipsel.deb
Size/MD5 checksum: 373696 603708cf407ea49748c987bea0ddaade
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_mipsel.deb
Size/MD5 checksum: 182958 5397950eb709142774a2aa70f5faa9db

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_mipsel.deb
Size/MD5 checksum: 343660 985465f428571c774bb3b44699768c15
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_mipsel.deb
Size/MD5 checksum: 915010 0553eb273d500c82b93cac55b7c52ad4

PowerPC architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_powerpc.deb
Size/MD5 checksum: 356590 f97bc218912092bae051188dd9c157d5
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_powerpc.deb
Size/MD5 checksum: 194062 b37b9d75744323dafdc4a76293c3456d

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_powerpc.deb
Size/MD5 checksum: 376486 bdfb8d5a839f65286e57e34857fd14f1
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_powerpc.deb
Size/MD5 checksum: 916952 90f7f069508d26431cc61f967886b159

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_s390.deb
Size/MD5 checksum: 329398 2b6046a2aeb468a00abc8556676d10d1
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_s390.deb
Size/MD5 checksum: 184216 78803336930258db2d7b115c4b708fad

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_s390.deb
Size/MD5 checksum: 360282 a7bb4f832d6a4d86753b3d046f4e8fa1
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_s390.deb
Size/MD5 checksum: 857396 e7efd1f4a92ba1f6a1a3c96e5c5a851b

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/libx/libxml/libxml-dev_1.8.17-2woody1_sparc.deb
Size/MD5 checksum: 347058 88ec785a5184e9ff44e617638b661be4
http://security.debian.org/pool/updates/main/libx/libxml/libxml1_1.8.17-2woody1_sparc.deb
Size/MD5 checksum: 196108 da3f13d8c4e4ffd8604cd01cf26c781f

http://security.debian.org/pool/updates/main/libx/libxml2/libxml2_2.4.19-4woody1_sparc.deb
Size/MD5 checksum: 363670 ab415cd91562622e7ab2dde1df98a09b
http://security.debian.org/pool/updates/main/libx/libxml2/libxml2-dev_2.4.19-4woody1_sparc.deb
Size/MD5 checksum: 886976 ba693e42209a963c26f325d89ecbe989

These files will probably be moved into the stable distribution on
its next revision.

----------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>


Bookmark and Share

« Microsoft iSNS Server Release Candidate version 2.2 · Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1 »

Linux Compatible » News » March 2004 » DSA 455-1: New libxml packages fix arbitrary code execution
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition