USN-3235-1: libxml2 vulnerabilities Ubuntu Security Notice USN-3235-1 16th March, 2017 libxml2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in libxml2. Software description libxml2 – GNOME XML library Details It was discovered that libxml2 incorrectly handled format strings. If auser or automated system were tricked into opening a specially crafteddocument, an attacker could possibly cause libxml2 to crash, resulting in adenial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04LTS, and Ubuntu 16.04 LTS. (CVE-2016-4448) It was discovered that libxml2 incorrectly handled certain malformeddocuments. If a user or automated system were tricked into opening aspecially crafted document, an attacker could cause libxml2 to crash,resulting in a denial of service, or possibly execute arbitrary code.(CVE-2016-4658) Nick Wellnhofer discovered [ more… ]