Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 865727

Summary: <dev-libs/libxml2-2.10.0: Multiple vulnerabilities
Product: Gentoo Security Reporter: Sam James <sam>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: base-system, sam
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
See Also: https://bugs.gentoo.org/show_bug.cgi?id=856598
Whiteboard: A2 [glsa+]
Package list:
Runtime testing required: ---
Bug Depends on: 876217    
Bug Blocks:    

Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-08-19 00:50:37 UTC
libxml2 2.10.0 release notes (https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.0#security) contain:
"""
Security

[CVE-2022-2309] Reset nsNr in xmlCtxtReset
Reserve byte for NUL terminator and report errors consistently in xmlBuf and
xmlBuffer (David Kilzer)
Fix missing NUL terminators in xmlBuf and xmlBuffer functions (David Kilzer)
Fix integer overflow in xmlBufferDump() (David Kilzer)
xmlBufAvail() should return length without including a byte for NUL
terminator (David Kilzer)
Fix ownership of xmlNodePtr & xmlAttrPtr fields in xmlSetTreeDoc() (David
Kilzer)
Use xmlNewDocText in xmlXIncludeCopyRange
Fix use-after-free bugs when calling xmlTextReaderClose() before
xmlFreeTextReader() on post-validating parser (David Kilzer)
Use UPDATE_COMPAT() consistently in buf.c (David Kilzer)
fix: xmlXPathParserContext could be double-delete in  OOM case. (jinsub ahn)
"""
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-10-14 03:32:22 UTC
GLSA request filed
Comment 2 Larry the Git Cow gentoo-dev 2022-10-16 14:45:55 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=adf5474fd11ba8a07548c5e37fac5e66db57a112

commit adf5474fd11ba8a07548c5e37fac5e66db57a112
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2022-10-16 14:40:08 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2022-10-16 14:45:20 +0000

    [ GLSA 202210-03 ] libxml2: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/833809
    Bug: https://bugs.gentoo.org/842261
    Bug: https://bugs.gentoo.org/865727
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202210-03.xml | 45 +++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 45 insertions(+)
Comment 3 Larry the Git Cow gentoo-dev 2022-10-28 19:53:26 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7d5c71d4ba751dd64e43e286c27b0b2fa5f1cc00

commit 7d5c71d4ba751dd64e43e286c27b0b2fa5f1cc00
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2022-10-28 19:32:57 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-10-28 19:50:00 +0000

    dev-libs/libxml2: drop 2.9.14-r1
    
    Bug: https://bugs.gentoo.org/865727
    Signed-off-by: Sam James <sam@gentoo.org>

 dev-libs/libxml2/Manifest                 |   2 -
 dev-libs/libxml2/libxml2-2.9.14-r1.ebuild | 187 ------------------------------
 2 files changed, 189 deletions(-)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-10-30 03:28:40 UTC
All done!