Debian Security Advisory

DLA-503-1 libxml2 -- LTS security update

Date Reported:
03 Jun 2016
Affected Packages:
libxml2
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 812807, Bug 813613, Bug 819006, Bug 823405, Bug 823414.
In Mitre's CVE dictionary: CVE-2015-8806, CVE-2016-1762, CVE-2016-1833, CVE-2016-1834, CVE-2016-1835, CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, CVE-2016-1840, CVE-2016-2073, CVE-2016-3627, CVE-2016-3705, CVE-2016-4447, CVE-2016-4449, CVE-2016-4483.
More information:

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause a denial-of-service against the application, or potentially the execution of arbitrary code with the privileges of the user running the application.

For Debian 7 Wheezy, these problems have been fixed in version 2.8.0+dfsg1-7+wheezy6.

We recommend that you upgrade your libxml2 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS