libxml2: Denial of service Multiple Denial of Services vulnerabilities were found in libxml2. libxml2 2010-09-21 2010-09-21 280617 remote 2.7.3-r2 2.7.3-r2

libxml2 is a library to manipulate XML files.

The following vulnerabilities were reported after a test with the Codenomicon XML fuzzing framework:

A remote attacker could entice a user or automated system to open a specially crafted XML document with an application using libxml2 resulting in a Denial of Service condition.

There is no known workaround at this time.

All libxml2 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/libxml2-2.7.3-r2"

NOTE: This is a legacy GLSA. Updates for all affected architectures are available since August 30, 2009. It is likely that your system is already no longer affected by this issue.

CVE-2009-2414 CVE-2009-2416 a3li craig vorlon