OracleVM 3.3 / 3.4 : libxml2 (OVMSA-2016-0087)

critical Nessus Plugin ID 91800

Synopsis

The remote OracleVM host is missing one or more security updates.

Description

The remote OracleVM system is missing necessary patches to address critical security updates :

- Update doc/redhat.gif in tarball

- Add libxml2-oracle-enterprise.patch and update logos in tarball

- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)

- Bug 763071: Heap-buffer-overflow in xmlStrncat (CVE-2016-1834)

- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup (CVE-2016-1840)

- Bug 758588: Heap-based buffer overread in xmlParserPrintFileContextInternal (CVE-2016-1838)

- Bug 758605: Heap-based buffer overread in xmlDictAddString (CVE-2016-1839)

- Bug 759398: Heap use-after-free in xmlDictComputeFastKey (CVE-2016-1836)

- Fix inappropriate fetch of entities content (CVE-2016-4449)

- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)

- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)

- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)

- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)

- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)

- Avoid building recursive entities (CVE-2016-3627)

- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)

- More format string warnings with possible format string vulnerability (CVE-2016-4448)

- Fix large parse of file from memory (rhbz#862969)

Solution

Update the affected libxml2 / libxml2-python packages.

See Also

https://bugzilla.gnome.org/show_bug.cgi?id=758605

https://bugzilla.gnome.org/show_bug.cgi?id=759398

https://oss.oracle.com/pipermail/oraclevm-errata/2016-June/000502.html

https://oss.oracle.com/pipermail/oraclevm-errata/2016-June/000501.html

https://bugzilla.gnome.org/show_bug.cgi?id=757711

https://bugzilla.gnome.org/show_bug.cgi?id=758588

Plugin Details

Severity: Critical

ID: 91800

File Name: oraclevm_OVMSA-2016-0087.nasl

Version: 2.7

Type: local

Published: 6/24/2016

Updated: 1/4/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:libxml2, p-cpe:/a:oracle:vm:libxml2-python, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/23/2016

Vulnerability Publication Date: 3/24/2016

Reference Information

CVE: CVE-2016-1762, CVE-2016-1833, CVE-2016-1834, CVE-2016-1835, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, CVE-2016-1840, CVE-2016-3627, CVE-2016-3705, CVE-2016-4447, CVE-2016-4448, CVE-2016-4449