An issue has been found in libxml2, the GNOME XML library.
This issue is called “Parameter Laughs”-attack and is related to parameter entities expansion. It is similar to the “Billion Laughs”-attacks found earlier in libexpat. More information can be found at 
For Debian 8 jessie, these problems have been fixed in version 2.9.1+dfsg1-5+deb8u11.
We recommend that you upgrade your libxml2 packages.
Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/