-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ## ## Patch description of patch ebcaf61f6debd12131a1753d095345dd ## Kind: security Shortdescription.english: Security update for libxml Longdescription.english: Applies to Package: libxml,libxml-devel Product(s): Release: 20041223 Obsoletes: none Indications Everyone should update. Contraindications None. Problem description This update adds missing patches for a buffer overflow in URL parsing code (CAN-2004-0989) and a buffer overflow while handling DNS responses (CAN-2004-0110). This bugs can be exploited remotely to execute arbitrary code. Solution Please install the updates provided at the location noted below. Installation notes This update is provided as an RPM package that can easily be installed onto a running system by using this command: rpm -Fvh libxml.rpm libxml-devel.rpm Hsilgne.noitpircsedgnol: Size: 483 MinYaST1Version: MinYaST2Version: UpdateOnlyInstalled: true Packages: ## ## -----> libxml <----- ## Filename: libxml.rpm Label: Library to manipulate XML files (version 1) Series: i586 Size: 572157 203630 PatchRpmBasedOn: 1.8.17-104 PatchRpmSize: 572157 188638 Buildtime: 1103556898 DepAND: DepOR: DepExcl: Flag: Category: RpmGroup: System/Libraries Copyright: Other License(s), see package, LGPL AuthorName: Daniel Veillard Raja R Harinath Tom Tromey Christopher Blizzard AuthorAddress: Version: 1.8.17-372 StartCommand: Obsoletes: Requires: ld-linux.so.2 libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libc.so.6(GLIBC_2.1.3) libz.so.1 rpmlib(PayloadIsBzip2) <= 3.0.5-1 Provides: libxml libxml.so.1 ## ## -----> libxml-devel <----- ## Filename: libxml-devel.rpm Label: libxml development package (version1) Series: i586 Size: 1628809 291054 PatchRpmBasedOn: 1.8.17-104 PatchRpmSize: 1628809 182496 Buildtime: 1103556898 DepAND: DepOR: DepExcl: Flag: Category: RpmGroup: Development/Libraries/C and C++ Copyright: Other License(s), see package, LGPL AuthorName: cf. package "libxml" AuthorAddress: Version: 1.8.17-372 StartCommand: Obsoletes: Requires: libxml /bin/sh rpmlib(PayloadIsBzip2) <= 3.0.5-1 Provides: Segakcap: -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFB2p0mqE7a6JyACsoRAgD4AJ9mKo2n7NT2Ad0LOpNH4G/xHgLAswCf dgZS9aMxO6hYc1afOefQweq2kGQ= =Zulh -----END PGP SIGNATURE-----