Bug 1088279 - (CVE-2018-9251) VUL-1: CVE-2018-9251: libxml2: The xz_decomp function in xzlib.c allows remote attackers to cause a denial of service (infinite loop) via acrafted XML file that triggers LZMA_MEMLIMIT_ERROR
(CVE-2018-9251)
VUL-1: CVE-2018-9251: libxml2: The xz_decomp function in xzlib.c allows remot...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/203141/
CVSSv2:NVD:CVE-2018-9251:2.6:(AV:N/A...
:
Depends on: CVE-2017-18258
Blocks:
  Show dependency treegraph
 
Reported: 2018-04-05 10:52 UTC by Karol Babioch
Modified: 2021-10-04 16:35 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-04-05 10:52:04 UTC
CVE-2018-9251

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-9251
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-9251.html
https://bugzilla.gnome.org/show_bug.cgi?id=794914
Comment 4 Pedro Monreal Gonzalez 2018-09-06 08:50:43 UTC
Fixed in https://bugzilla.suse.com/show_bug.cgi?id=1105166#c3
Comment 6 Swamp Workflow Management 2018-10-09 13:08:47 UTC
SUSE-SU-2018:3080-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1088279,1102046,1105166
CVE References: CVE-2018-14404,CVE-2018-14567,CVE-2018-9251
Sources used:
SUSE Linux Enterprise Module for Basesystem 15 (src):    libxml2-2.9.7-3.3.1, python-libxml2-python-2.9.7-3.3.1
Comment 7 Swamp Workflow Management 2018-10-09 13:09:48 UTC
SUSE-SU-2018:3081-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1088279,1088601,1102046,1105166
CVE References: CVE-2017-18258,CVE-2018-14404,CVE-2018-14567,CVE-2018-9251
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    libxml2-2.9.4-46.15.1
SUSE Linux Enterprise Server 12-SP3 (src):    libxml2-2.9.4-46.15.1, python-libxml2-2.9.4-46.15.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    libxml2-2.9.4-46.15.1, python-libxml2-2.9.4-46.15.1
SUSE CaaS Platform ALL (src):    libxml2-2.9.4-46.15.1
SUSE CaaS Platform 3.0 (src):    libxml2-2.9.4-46.15.1
OpenStack Cloud Magnum Orchestration 7 (src):    libxml2-2.9.4-46.15.1
Comment 8 Swamp Workflow Management 2018-10-12 10:10:24 UTC
openSUSE-SU-2018:3107-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1088279,1088601,1102046,1105166
CVE References: CVE-2017-18258,CVE-2018-14404,CVE-2018-14567,CVE-2018-9251
Sources used:
openSUSE Leap 42.3 (src):    libxml2-2.9.4-18.1, python-libxml2-2.9.4-18.1
Comment 9 Swamp Workflow Management 2018-10-12 10:13:06 UTC
openSUSE-SU-2018:3110-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1088279,1102046,1105166
CVE References: CVE-2018-14404,CVE-2018-14567,CVE-2018-9251
Sources used:
openSUSE Leap 15.0 (src):    libxml2-2.9.7-lp150.2.3.1, python-libxml2-python-2.9.7-lp150.2.3.1
Comment 10 Marcus Meissner 2019-08-31 14:39:34 UTC
done