Issue metadata
Sign in to add a comment
|
CrOS: Vulnerability reported in dev-libs/libxml2 |
||||||||||||||||||||||
Issue descriptionAutomated analysis has detected that the following third party packages have had vulnerabilities publicly reported. NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package. Package Name: dev-libs/libxml2 Package Version: [cpe:/a:xmlsoft:libxml2:2.9.4] Advisory: CVE-2016-4483 Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2016-4483 CVSS severity score: 5/10.0 Confidence: high Description: The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627.
,
Jan 7 2018
,
Jan 7 2018
I have made this a duplicate of crbug.com/799707 . This bug will be fixed next time someone does a roll from libxml. Since this particular bug is not critical, and I have some outstanding patches with libxml, I'm planning to wait until my patches are taken by libxml before rolling.
,
Jan 9 2018
as noted in the other issue: Chrome OS system is already on libxml2-2.9.6, so this only impacts Chrome itself
,
Jun 30 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by metzman@chromium.org
, Jan 7 2018Labels: -Pri-2 Security_Severity-Low Pri-3
Owner: joelhockey@chromium.org
Status: Unconfirmed (was: Untriaged)