Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2009-316

Mandriva Linux Security Advisory 2009-316 – The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than and CVE-2009-3720. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers This update provides a solution to these vulnerabilities. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. SUSE discovered a regression with the previous patch fixing CVE-2009-3560. This regression is now being addressed with this update.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/84964/MDVSA-2009-316-2.txt

Source: https://packetstormsecurity.com/files/84964/Mandriva-Linux-Security-Advisory-2009-316.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.061