Issue metadata
Sign in to add a comment
|
CrOS: Vulnerability reported in dev-libs/libxml2 |
||||||||||||||||||||
Issue descriptionAutomated analysis has detected that the following third party packages have had vulnerabilities publicly reported. NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package. Package Name: dev-libs/libxml2 Package Version: [cpe:/a:xmlsoft:libxml2:2.9.6] Advisory: CVE-2017-18258 Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-18258 CVSS severity score: 4.3/10.0 Confidence: high Description: The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
,
May 19 2018
,
May 21 2018
CrOS upgraded to 2.9.6 in at least R66 I think the CPE details are off though ... the report says the bug is <2.9.6, but the CPE seems to match <=2.9.6.
,
Jul 27
,
Aug 25
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by xzhou@chromium.org
, May 18 2018Status: Fixed (was: Untriaged)