Summary
The remote host is missing an update to libxml2
announced via advisory DSA 1461-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201461-1
Insight
Brad Fitzpatrick discovered that the UTF-8 decoding functions of libxml2, the GNOME XML library, validate UTF-8 correctness insufficiently, which may lead to denial of service by forcing libxml2 into an infinite loop.
For the unstable distribution (sid), this problem will be fixed soon.
For the stable distribution (etch), this problem has been fixed in version 2.6.27.dfsg-2.
For the old stable distribution (sarge), this problem has been fixed in version 2.6.16-7sarge1.
We recommend that you upgrade your libxml2 packages.
Severity
Classification
-
CVE CVE-2007-6284 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities