Debian Linux Security Advisory 2652-1 - Brad Hill of iSEC Partners discovered that many XML implementations are vulnerable to external entity expansion issues, which can be used for various purposes such as firewall circumvention, disguising an IP address, and denial-of-service. libxml2 was susceptible to these problems when performing string substitution during entity expansion.
04ec56e7cfa9d1647f6ba4df2f17ae024aed83c6e87c37677e43bc3a80341400
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2652-1 security@debian.org
https://www.debian.org/security/ Michael Gilbert
March 24, 2013 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libxml2
Vulnerability : external entity expansion
Problem type : remote
Debian-specific: no
CVE ID : CVE-2013-0338 CVE-2013-0339
Debian Bug : 702260
Brad Hill of iSEC Partners discovered that many XML implementations are
vulnerable to external entity expansion issues, which can be used for
various purposes such as firewall circumvention, disguising an IP
address, and denial-of-service. libxml2 was susceptible to these
problems when performing string substitution during entity expansion.
For the stable distribution (squeeze), these problems have been fixed in
version 2.7.8.dfsg-2+squeeze7.
For the testing (wheezy) and unstable (sid) distributions, these problems
have been fixed in version 2.8.0+dfsg1-7+nmu1.
We recommend that you upgrade your libxml2 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iQEcBAEBAgAGBQJRUMJsAAoJEL97/wQC1SS+PAcH/1wNl75mW7tMRlNLoI2QIrIy
bSjxCmdl8WELMYpujnP4wxPRzE8p0WoIUVH3z73TMromx+4U4y1skgJBC2xmeIb1
ei76dpw4QgkoIrn9OCauXBzDKpXToYDlSxY6Kwk1qiBGymukDPQMHcgb5q9AmEYP
5FsunANzVhRQt83UORBb8+W6JPmmaJpGiswFiWXAlCJy5mBdEcWHFOfGfAZZ+ZxJ
VOPPiulNTpEVttDtfqNWp2VOf5LmVW73Y+C+OgCcNL5tEJQEwxqIwMPlUcf5DQEb
lZHJa1BGNwcNZZgSG8d5SL0cwn0rWLRIIdbqZvus+s2yMcQcBTn1hLd1yaCVmaU=
=kczj
-----END PGP SIGNATURE-----