missing patch in USN-2834-1 security updates
Bug #1525996 reported by
Marc Deslauriers
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
libxml2 (Ubuntu) |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Precise |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Trusty |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Vivid |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Wily |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Xenial |
Fix Released
|
Undecided
|
Marc Deslauriers |
Bug Description
USN-2834-1 contained a fix for CVE-2015-7499, but did not contain the following subsequent commit:
https:/
See post from Tom Lane here:
http://<email address hidden>
Changed in libxml2 (Ubuntu Precise): | |
status: | New → Confirmed |
Changed in libxml2 (Ubuntu Trusty): | |
status: | New → Confirmed |
Changed in libxml2 (Ubuntu Vivid): | |
status: | New → Confirmed |
Changed in libxml2 (Ubuntu Wily): | |
status: | New → Confirmed |
Changed in libxml2 (Ubuntu Xenial): | |
status: | New → Confirmed |
Changed in libxml2 (Ubuntu Precise): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in libxml2 (Ubuntu Trusty): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in libxml2 (Ubuntu Vivid): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in libxml2 (Ubuntu Wily): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in libxml2 (Ubuntu Xenial): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
To post a comment you must log in.
This bug was fixed in the package libxml2 - 2.9.2+zdfsg1- 4ubuntu3
--------------- zdfsg1- 4ubuntu3) xenial; urgency=medium
libxml2 (2.9.2+
* SECURITY UPDATE: incomplete fix for out of bounds read in xmlGROW patches/ CVE-2015- 7499-3. patch: reuse xmlHaltParser() where it patches/ CVE-2015- 7499-4. patch: do not print error context when patches/ CVE-2015- 8710.patch: fix parsing short unclosed
(LP: #1525996)
- add extra commits to this previously-fixed CVE
- debian/
makes sense in parser.c.
- debian/
there is none in error.c.
- CVE-2015-7499
* SECURITY UPDATE: out of bounds memory access via unclosed html comment
- debian/
comment uninitialized access in HTMLparser.c.
- CVE-2015-8710
-- Marc Deslauriers <email address hidden> Thu, 14 Jan 2016 08:59:31 -0500