Amazon Linux 1 Security Advisory: ALAS-2013-188
Advisory Release Date: 2013-05-13 10:28 Pacific
Advisory Updated Date: 2014-09-15 23:02 Pacific
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.
Affected Packages:
libxml2
Issue Correction:
Run yum update libxml2 to update your system.
i686:
libxml2-debuginfo-2.7.8-10.26.amzn1.i686
libxml2-static-2.7.8-10.26.amzn1.i686
libxml2-devel-2.7.8-10.26.amzn1.i686
libxml2-2.7.8-10.26.amzn1.i686
libxml2-python-2.7.8-10.26.amzn1.i686
src:
libxml2-2.7.8-10.26.amzn1.src
x86_64:
libxml2-static-2.7.8-10.26.amzn1.x86_64
libxml2-2.7.8-10.26.amzn1.x86_64
libxml2-devel-2.7.8-10.26.amzn1.x86_64
libxml2-debuginfo-2.7.8-10.26.amzn1.x86_64
libxml2-python-2.7.8-10.26.amzn1.x86_64