ALAS-2013-188


Amazon Linux AMI Security Advisory: ALAS-2013-188
Advisory Release Date: 2014-09-15 23:02 Pacific
Severity: Medium
References: CVE-2013-0338 

Issue Overview:

libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.


Affected Packages:

libxml2


Issue Correction:
Run yum update libxml2 to update your system.

New Packages:
i686:
    libxml2-debuginfo-2.7.8-10.26.amzn1.i686
    libxml2-static-2.7.8-10.26.amzn1.i686
    libxml2-devel-2.7.8-10.26.amzn1.i686
    libxml2-2.7.8-10.26.amzn1.i686
    libxml2-python-2.7.8-10.26.amzn1.i686

src:
    libxml2-2.7.8-10.26.amzn1.src

x86_64:
    libxml2-static-2.7.8-10.26.amzn1.x86_64
    libxml2-2.7.8-10.26.amzn1.x86_64
    libxml2-devel-2.7.8-10.26.amzn1.x86_64
    libxml2-debuginfo-2.7.8-10.26.amzn1.x86_64
    libxml2-python-2.7.8-10.26.amzn1.x86_64