Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 597112 (CVE-2016-4658) - <dev-libs/libxml2-2.9.4-r1: Use after free via namespace node in XPointer ranges (CVE-2016-4658)
Summary: <dev-libs/libxml2-2.9.4-r1: Use after free via namespace node in XPointer ran...
Status: RESOLVED FIXED
Alias: CVE-2016-4658
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: A2 [glsa cve blocked]
Keywords:
Depends on: 597116
Blocks:
  Show dependency tree
 
Reported: 2016-10-14 14:03 UTC by Agostino Sarubbo
Modified: 2017-01-16 21:26 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-10-14 14:03:27 UTC
From ${URL} :

Possible use after free vulnerability via namespace nodes in XPointer ranges was found.

Upstream patch:

https://git.gnome.org/browse/libxml2/commit/?id=c1d1f7121194036608bf555f08d3062a36fd344b


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2016-11-19 00:55:35 UTC
CVE-2016-4658 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4658):
  libxml2 in Apple iOS before 10, OS X before 10.12, tvOS before 10, and
  watchOS before 3 allows remote attackers to execute arbitrary code or cause
  a denial of service (memory corruption) via a crafted XML document.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-11-19 01:01:21 UTC
Patch not present in 2.9.4.  Will require addition in tree or await upstream inclusion.
Comment 3 Teika kazura 2016-12-24 07:17:58 UTC
You may already know it, but Debian released a fix for CVE-2016-4658 (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=840553) and CVE-2016-5131 (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=840554). See also https://www.debian.org/security/2016/dsa-3744

This release is Debian's own one, though the patches are in the upstream repo. Upstream has not fixed CVE-2016-9318 which affects libxml2-2.9.4 and earliear.

BTW the last CVE item does not seem to be reported to Gentoo.

(I made an almost identical comment at https://bugs.gentoo.org/show_bug.cgi?id=589816#c8)

Thanks Gentoo devs. Best regards.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2017-01-16 21:26:31 UTC
This issue was resolved and addressed in
 GLSA 201701-37 at https://security.gentoo.org/glsa/201701-37
by GLSA coordinator Thomas Deutschmann (whissi).