Bug 1078806 - (CVE-2017-5130) VUL-0: CVE-2017-5130: libxml2: remote buffer overflow
(CVE-2017-5130)
VUL-0: CVE-2017-5130: libxml2: remote buffer overflow
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/193527/
CVSSv3:SUSE:CVE-2017-5130:8.8:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-02-01 15:44 UTC by Marcus Meissner
Modified: 2019-09-25 17:55 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
Patches for SLE-1{0,1,2} (1.33 KB, application/gzip)
2018-02-02 13:52 UTC, Pedro Monreal Gonzalez
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2018-02-01 15:44:44 UTC
Details via rh analysis:

The affected function xmlMemoryStrdup() is a debug-only function that should never be called in production builds. The only exception is xmllint when invoked with --maxmem. The same issue applies to

xmlMallocLoc
xmlReallocLoc

This issue is fixed via the following upstream commit:

https://git.gnome.org/browse/libxml2/commit/?id=897dffbae322b46b83f99a607d527058a72c51ed

Referenced at:

https://bugzilla.gnome.org/show_bug.cgi?id=783026 (currently private)
Comment 1 Marcus Meissner 2018-02-01 15:46:32 UTC
I can access https://bugzilla.gnome.org/show_bug.cgi?id=783026 for details (when logged in).
Comment 2 Pedro Monreal Gonzalez 2018-02-02 13:51:19 UTC
Packages submitted:

openSUSE:Factory        2.9.7   Fixed upstream
SUSE:SLE-15             2.9.7   Fixed upstream
SUSE:SLE-12-SP2:Update  2.9.4   libxml2-2.9.4-CVE-2017-5130.patch  sr#153759
SUSE:SLE-11-SP1:Update  2.7.6   libxml2-2.7.6-CVE-2017-5130.patch  sr#153763
SUSE:SLE-10-SP3:Update  2.6.23  libxml2-2.6.23-CVE-2017-5130.patch sr#153764
Comment 3 Pedro Monreal Gonzalez 2018-02-02 13:52:09 UTC
Created attachment 758615 [details]
Patches for SLE-1{0,1,2}
Comment 6 Swamp Workflow Management 2018-02-06 12:28:38 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2018-02-20.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/63962
Comment 7 Swamp Workflow Management 2018-02-08 11:11:54 UTC
SUSE-SU-2018:0395-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1069689,1077993,1078806,1078813
CVE References: CVE-2016-5131,CVE-2017-15412,CVE-2017-16932,CVE-2017-5130
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    libxml2-2.7.6-0.77.10.1
SUSE Linux Enterprise Server 11-SP4 (src):    libxml2-2.7.6-0.77.10.1, libxml2-python-2.7.6-0.77.10.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    libxml2-2.7.6-0.77.10.1, libxml2-python-2.7.6-0.77.10.1
Comment 8 Swamp Workflow Management 2018-02-08 20:07:41 UTC
SUSE-SU-2018:0401-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1077993,1078806,1078813
CVE References: CVE-2016-5131,CVE-2017-15412,CVE-2017-5130
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    libxml2-2.9.4-46.12.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    libxml2-2.9.4-46.12.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    libxml2-2.9.4-46.12.1, python-libxml2-2.9.4-46.12.1
SUSE Linux Enterprise Server 12-SP3 (src):    libxml2-2.9.4-46.12.1, python-libxml2-2.9.4-46.12.1
SUSE Linux Enterprise Server 12-SP2 (src):    libxml2-2.9.4-46.12.1, python-libxml2-2.9.4-46.12.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    libxml2-2.9.4-46.12.1, python-libxml2-2.9.4-46.12.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    libxml2-2.9.4-46.12.1, python-libxml2-2.9.4-46.12.1
SUSE CaaS Platform ALL (src):    libxml2-2.9.4-46.12.1
OpenStack Cloud Magnum Orchestration 7 (src):    libxml2-2.9.4-46.12.1
Comment 9 Swamp Workflow Management 2018-02-09 23:08:22 UTC
openSUSE-SU-2018:0418-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1077993,1078806,1078813
CVE References: CVE-2016-5131,CVE-2017-15412,CVE-2017-5130
Sources used:
openSUSE Leap 42.3 (src):    libxml2-2.9.4-15.1, python-libxml2-2.9.4-15.1
Comment 10 Marcus Meissner 2018-02-10 10:41:00 UTC
released