Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 245960
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
libxml2-CVE-2008-4225.patch libxml2-CVE-2008-4225.patch patch Robert Buchholz 2008-11-07 13:33 0000 821 bytes Details | Diff
libxml2-CVE-2008-4226.patch libxml2-CVE-2008-4226.patch patch Robert Buchholz 2008-11-07 13:34 0000 706 bytes Details | Diff
libxml2-2.7.2-r1.ebuild Straight-forward preebuild text/plain Mart Raudsepp 2008-11-17 04:12 0000 3.57 KB Details
libxml2-2.7.2-CVE-2008-4225.patch libxml2-2.7.2-CVE-2008-4225.patch patch Robert Buchholz 2008-11-17 18:19 0000 799 bytes Details | Diff
libxml2-2.7.2-CVE-2008-4226.patch libxml2-2.7.2-CVE-2008-4226.patch patch Robert Buchholz 2008-11-17 18:19 0000 1.17 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 245960 depends on: Show dependency tree
Bug 245960 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-11-07 13:26 0000
** Please note that this issue is confidential and no information should be
disclosed until it is made public, see "Whiteboard" for a date **

Drew Yao of Apple Product Security reported two issues in libxml

CVE-2008-4225:
A maliciously crafted xml file could cause the application to go into an
infinite loop, leading to a denial of service. It requires a very  
large xml file to trigger the bug, but it's very common to parse  
compressed xml files, and the file compresses well.

CVE-2008-4226:
A maliciously crafted xml file could cause an integer overflow leading to
memory corruption and potential arbitrary code execution. It requires a very  
large xml file to trigger the bug, but it's very common to parse  
compressed xml files, and the file compresses well.

------- Comment #1 From Robert Buchholz 2008-11-07 13:33:53 0000 -------
Created an attachment (id=170985) [details]
libxml2-CVE-2008-4225.patch

Patches are provided by Drew Yao and not approved by upstream yet

------- Comment #2 From Robert Buchholz 2008-11-07 13:34:06 0000 -------
Created an attachment (id=170987) [details]
libxml2-CVE-2008-4226.patch

------- Comment #3 From Mart Raudsepp 2008-11-08 18:14:11 0000 -------
Waiting a bit then for upstream response on the patches before providing a
preebuild. Please let us know if there is any response on that, or feel free to
remind us for a preebuild 4-7 days before confidential end date

------- Comment #4 From Mart Raudsepp 2008-11-08 18:15:41 0000 -------
And sample compressed XML files would be nice for testing. Attached or sent via
e-mail, as appropriate

------- Comment #5 From Robert Buchholz 2008-11-08 20:53:19 0000 -------
Mart, I'll mail it to you.

------- Comment #6 From Mart Raudsepp 2008-11-17 04:12:55 0000 -------
Created an attachment (id=172041) [details]
Straight-forward preebuild

The first patch is a no-go for me, as even my standard amd64 system doesn't
have SIZE_T_MAX available:

SAX2.c:2459: error: 'SIZE_T_MAX' undeclared (first use in this function)

Nevertheless here's the obvious ebuild that patches those two patches in, so it
can be seen it fails... Note that I intend to rename the patches to include the
version number (${P} instead of ${PN}) in the version that goes into portage
tree once the bugs are disclosed and there's working patches, but don't think I
should hassle the arch teams with renaming the patches as saved off of the
attachments here for that. The end result will have comment in the ebuild
stating what they do as well, once a good description is available from
publicly viewable CVE records.

Any updates, especially for the platform compatibility, from vendor-sec? Though
it shouldn't be hard to fix it ourselves too to compile, but...

------- Comment #7 From Robert Buchholz 2008-11-17 18:18:42 0000 -------
This is now public, Daniel Veillard provided more portable patches (which he
probably applied upstream).

------- Comment #8 From Robert Buchholz 2008-11-17 18:19:18 0000 -------
Created an attachment (id=172099) [details]
libxml2-2.7.2-CVE-2008-4225.patch

------- Comment #9 From Robert Buchholz 2008-11-17 18:19:37 0000 -------
Created an attachment (id=172101) [details]
libxml2-2.7.2-CVE-2008-4226.patch

------- Comment #10 From Mart Raudsepp 2008-11-18 01:27:05 0000 -------
libxml2-2.7.2-r1 is in the tree with the patch that was committed upstream,
which is the both combined, plus some extra safeguards for possible future
found problems in parser.c (if I read that right).

Target keywords for dev-libs/libxml2-2.7.2-r1 - everyone:
alpha amd64 arm hppa ia64 m68k ppc ppc64 s390 sh sparch x86

------- Comment #11 From Ferris McCormick 2008-11-18 13:38:15 0000 -------
Sparc stable, all tests run successfully.

------- Comment #12 From Jeroen Roovers 2008-11-18 15:04:16 0000 -------
Stable for HPPA.

------- Comment #13 From Tobias Scherbaum 2008-11-18 17:47:03 0000 -------
ppc stable

------- Comment #14 From Markus Meier 2008-11-19 22:23:43 0000 -------
amd64/x86 stable

------- Comment #15 From Raúl Porcel 2008-11-20 10:12:29 0000 -------
alpha/arm/ia64 stable

------- Comment #16 From Brent Baude 2008-11-24 17:01:35 0000 -------
ppc64 done

------- Comment #17 From Robert Buchholz 2008-12-02 17:46:50 0000 -------
GLSA 200812-06

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug