Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 25 Aug 2008 18:11:36 +0200
From: Tomas Hoger <thoger@...hat.com>
To: vdanen@...sec.ca
Cc: oss-security@...ts.openwall.com, vendor-sec@....de
Subject: Re: Re: libxml2 denial of service flaw
 (CVE-2008-3281)

On Mon, 25 Aug 2008 09:58:38 -0600 Vincent Danen <vdanen@...sec.ca>
wrote:

> Does anyone know if this affects anything other than librsvg?  If so,
> the patch approach to fixing libxml2 would be better.  I've just
> started looking into this today, so I'm not quite up to speed on
> this, but it looks like there are problems with the gnome menus as
> well.

librsvg and strigi are known to be affected, according to the Debian
bug.  Rebuild against new libxml2 should do the trick, if that's the
way you can go.

> Has anyone tried this new patch?

Being tested now.

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.