|
LinuxSecurity.com: libxml2 version 2.7.0 and 2.7.1 did not properly handle predefined entities definitions in entities, which allowed context-dependent attackers to cause a denial of service (memory consumption and application crash) via certain XML documents (CVE-2008-4409). The updated packages have been patched to prevent this issue.
Original Source: http://www.linuxsecurity.com/content/view/143147?rdf
Learn more about Mandriva: Subject: [Security Announce] [ MDVSA-2008:212 ] libxml2 |