Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 237806
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 237806 depends on: Show dependency tree
Bug 237806 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-09-16 02:18 0000
CVE-2008-3529 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3529):
  Heap-based buffer overflow in the xmlParseAttValueComplex function in
  parser.c in libxml2 before 2.7.0 allows context-dependent attackers
  to cause a denial of service (crash) or possibly execute arbitrary
  code via a long XML entity name.

------- Comment #1 From Robert Buchholz 2008-09-16 02:20:17 0000 -------
We need to patch this, and a fix for #234099 would be appreciated too. A
reproducer is available on request.

------- Comment #2 From Rémi Cardona 2008-09-16 07:52:56 0000 -------
Thing is, no-one has fixed librsvg. Or at least, I didn't find any patches for
it during my quick search yesterday.

So I really don't know what exactly we can do, except to start hacking on
librsvg...

Thoughts?

------- Comment #3 From Mart Raudsepp 2008-09-16 12:22:39 0000 -------
librsvg is not the only thing that breaks. Anything can break on an ABI break
of a struct that wasn't made private properly, we just only know about librsvg,
strigi and a few more (some of which might be due to using librsvg).
I was not successful with convincing upstream that ABI breaks are bad, and
should be treated like in glib and gtk+ - not done. So I need to patch this in
am ABI compatible way and include this one here. I hope I can work on that
later today after I'm done with some work work.

------- Comment #4 From Mart Raudsepp 2008-09-25 01:33:58 0000 -------
libxml2-2.7.0 restored ABI before release and it's fine afterall, as noted in
bug 234099. libxml2-2.7.1 is in the tree now, and also addresses the security
bug covered here, although note that with a different patch than in the
referenced URL.
I won't add arches myself, because bug 234099 already does so. security@,
please add them yourself if you deem that necessary.

------- Comment #5 From Tobias Heinlein 2008-10-01 21:26:00 0000 -------
GLSA request filed.

------- Comment #6 From Robert Buchholz 2008-12-02 17:46:30 0000 -------
GLSA 200812-06

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug