New issue
Advanced search Search tips

Issue 824101 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2018
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in dev-libs/libxml2

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Mar 21 2018

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: dev-libs/libxml2
Package Version: [cpe:/a:xmlsoft:libxml2:2.9.4]

Advisory: CVE-2017-7375
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-7375
  CVSS severity score: 7.5/10.0
  Confidence: high
  Description:

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).
Advisory: CVE-2017-7376
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-7376
  CVSS severity score: 10/10.0
  Confidence: high
  Description:

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.


 
Status: WontFix (was: Untriaged)
Re CVE-2017-7375: The Chrome OS libxml package (2.9.6) already carries the patch.

Re CVE-2017-7376: The Chrome OS libxml package (2.9.6) carries the upstream patch https://git.gnome.org/browse/libxml2/commit/?id=5dca9eea1bd4263bfa4d037ab2443de1cd730f7e

Both of these where part of https://source.android.com/security/bulletin/2017-06-01, so not sure why vomit rehashes them now.
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 27 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment