Upstream information
Description
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entry: 528370, 532345 SUSE Security Advisories:- SUSE-SR:2009:018, published Tue, 10 Nov 2009 13:00:00 +0000
List of released packages
List of products where fixes are in QA
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64TSUSE Linux Enterprise Desktop 10 SP3 for x86
