DSA-2479-1 libxml2 -- off-by-one

Related Vulnerabilities: CVE-2011-3102  

Jueri Aedla discovered an off-by-one in libxml2, which could result in the execution of arbitrary code. For the stable distribution (squeeze), this problem has been fixed in version 2.7.8.dfsg-2+squeeze4. For the unstable distribution (sid), this problem has been fixed in version 2.7.8.dfsg-9.1. We recommend that you upgrade your libxml2 packages.

Debian Security Advisory

DSA-2479-1 libxml2 -- off-by-one

Date Reported:
23 May 2012
Affected Packages:
libxml2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2011-3102.
More information:

Jueri Aedla discovered an off-by-one in libxml2, which could result in the execution of arbitrary code.

For the stable distribution (squeeze), this problem has been fixed in version 2.7.8.dfsg-2+squeeze4.

For the unstable distribution (sid), this problem has been fixed in version 2.7.8.dfsg-9.1.

We recommend that you upgrade your libxml2 packages.