{"affected":[{"ecosystem_specific":{"binaries":[{"libxml2-devel":"2.7.6-0.44.1","libxml2-devel-32bit":"2.7.6-0.44.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 5","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20OpenStack%20Cloud%205"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 5","name":"libxml2-python","purl":"pkg:rpm/suse/libxml2-python&distro=SUSE%20OpenStack%20Cloud%205"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Manager 2.1","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20Manager%202.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Manager 2.1","name":"libxml2-python","purl":"pkg:rpm/suse/libxml2-python&distro=SUSE%20Manager%202.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Manager Proxy 2.1","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20Manager%20Proxy%202.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Manager Proxy 2.1","name":"libxml2-python","purl":"pkg:rpm/suse/libxml2-python&distro=SUSE%20Manager%20Proxy%202.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP2-LTSS","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP2-LTSS","name":"libxml2-python","purl":"pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-LTSS","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-LTSS","name":"libxml2-python","purl":"pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","name":"libxml2-python","purl":"pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4","libxml2-x86":"2.7.6-0.44.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4","libxml2-x86":"2.7.6-0.44.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"libxml2-python","purl":"pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4","libxml2-x86":"2.7.6-0.44.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"libxml2","purl":"pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libxml2":"2.7.6-0.44.1","libxml2-32bit":"2.7.6-0.44.1","libxml2-doc":"2.7.6-0.44.1","libxml2-python":"2.7.6-0.44.4","libxml2-x86":"2.7.6-0.44.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"libxml2-python","purl":"pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.6-0.44.4"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis update for libxml2 fixes the following security issues: \n\n- CVE-2016-2073, CVE-2015-8806, CVE-2016-1839: A Heap-buffer overread\n  was fixed in libxml2/dict.c  [bsc#963963, bsc#965283, bsc#981114].\n- CVE-2016-4483: Code was added to avoid an out of bound access when\n  serializing malformed strings [bsc#978395].\n- CVE-2016-1762: Fixed a heap-based buffer overread in xmlNextChar [bsc#981040].\n- CVE-2016-1834: Fixed a heap-buffer-overflow in xmlStrncat [bsc#981041].\n- CVE-2016-1833: Fixed a heap-based buffer overread in htmlCurrentChar [bsc#981108].\n- CVE-2016-1835: Fixed a heap use-after-free in xmlSAX2AttributeNs [bsc#981109].\n- CVE-2016-1837: Fixed a heap use-after-free in htmlParsePubidLiteral\n  and htmlParseSystemiteral [bsc#981111].\n- CVE-2016-1838: Fixed a heap-based buffer overread in\n  xmlParserPrintFileContextInternal [bsc#981112].\n- CVE-2016-1840: Fixed a heap-buffer-overflow in xmlFAParsePosCharGroup [bsc#981115].\n- CVE-2016-4447: Fixed a heap-based buffer-underreads due to xmlParseName [bsc#981548].\n- CVE-2016-4448: Fixed some format string warnings with possible format\n  string vulnerability [bsc#981549],\n- CVE-2016-4449: Fixed inappropriate fetch of entities content [bsc#981550].\n- CVE-2016-3705: Fixed missing increment of recursion counter.\n","id":"SUSE-SU-2016:1604-1","modified":"2016-06-17T09:21:30Z","published":"2016-06-17T09:21:30Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2016/suse-su-20161604-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/963963"},{"type":"REPORT","url":"https://bugzilla.suse.com/965283"},{"type":"REPORT","url":"https://bugzilla.suse.com/978395"},{"type":"REPORT","url":"https://bugzilla.suse.com/981040"},{"type":"REPORT","url":"https://bugzilla.suse.com/981041"},{"type":"REPORT","url":"https://bugzilla.suse.com/981108"},{"type":"REPORT","url":"https://bugzilla.suse.com/981109"},{"type":"REPORT","url":"https://bugzilla.suse.com/981111"},{"type":"REPORT","url":"https://bugzilla.suse.com/981112"},{"type":"REPORT","url":"https://bugzilla.suse.com/981114"},{"type":"REPORT","url":"https://bugzilla.suse.com/981115"},{"type":"REPORT","url":"https://bugzilla.suse.com/981548"},{"type":"REPORT","url":"https://bugzilla.suse.com/981549"},{"type":"REPORT","url":"https://bugzilla.suse.com/981550"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-8806"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1762"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1835"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1837"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1838"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1839"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1840"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-2073"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-3705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-4447"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-4448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-4449"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-4483"}],"related":["CVE-2015-8806","CVE-2016-1762","CVE-2016-1833","CVE-2016-1834","CVE-2016-1835","CVE-2016-1837","CVE-2016-1838","CVE-2016-1839","CVE-2016-1840","CVE-2016-2073","CVE-2016-3705","CVE-2016-4447","CVE-2016-4448","CVE-2016-4449","CVE-2016-4483"],"summary":"Security update for libxml2","upstream":["CVE-2015-8806","CVE-2016-1762","CVE-2016-1833","CVE-2016-1834","CVE-2016-1835","CVE-2016-1837","CVE-2016-1838","CVE-2016-1839","CVE-2016-1840","CVE-2016-2073","CVE-2016-3705","CVE-2016-4447","CVE-2016-4448","CVE-2016-4449","CVE-2016-4483"]}