OracleVM 3.3 / 3.4 : libxml2 (OVMSA-2016-0087)

Critical Nessus Plugin ID 91800


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- Update doc/redhat.gif in tarball

- Add libxml2-oracle-enterprise.patch and update logos in tarball

- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)

- Bug 763071: Heap-buffer-overflow in xmlStrncat (CVE-2016-1834)

- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup (CVE-2016-1840)

- Bug 758588: Heap-based buffer overread in xmlParserPrintFileContextInternal (CVE-2016-1838)

- Bug 758605: Heap-based buffer overread in xmlDictAddString (CVE-2016-1839)

- Bug 759398: Heap use-after-free in xmlDictComputeFastKey (CVE-2016-1836)

- Fix inappropriate fetch of entities content (CVE-2016-4449)

- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)

- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)

- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)

- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)

- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)

- Avoid building recursive entities (CVE-2016-3627)

- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)

- More format string warnings with possible format string vulnerability (CVE-2016-4448)

- Fix large parse of file from memory (rhbz#862969)


Update the affected libxml2 / libxml2-python packages.

See Also

Plugin Details

Severity: Critical

ID: 91800

File Name: oraclevm_OVMSA-2016-0087.nasl

Version: $Revision: 2.4 $

Type: local

Published: 2016/06/24

Modified: 2017/02/14

Dependencies: 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:ND/RC:UR


Base Score: 9.8

Temporal Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:X/RC:R

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:libxml2, p-cpe:/a:oracle:vm:libxml2-python, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2016/06/23

Reference Information

CVE: CVE-2016-1762, CVE-2016-1833, CVE-2016-1834, CVE-2016-1835, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, CVE-2016-1840, CVE-2016-3627, CVE-2016-3705, CVE-2016-4447, CVE-2016-4448, CVE-2016-4449

OSVDB: 130651, 130653, 134833, 136114, 136194, 137962, 138565, 138566, 138567, 138568, 138569, 138570, 138571, 138572, 138926, 138928, 138966