oss-sec mailing list archives

Re: Re: libxml2 "ampproblem" DoS


From: "Steven M. Christey" <coley () linus mitre org>
Date: Fri, 3 Oct 2008 17:09:15 -0400 (EDT)


On Fri, 3 Oct 2008, Daniel Veillard wrote:

The malicious XML file can be found on
http://bugzilla.gnome.org/show_bug.cgi?id=554660

I'm not sure if and how this is related to CVE-2008-3281.

  It's unrelated, the patch is attached to the bug, only 2.7.x is affected
and I will release 2.7.2 within a couple of hours.

Use CVE-2008-4422

- Steve


Current thread: