Bug 769182 (CVE-2012-2825) - VUL-0: CVE-2012-2825: libxslt invalid read crash
Summary: VUL-0: CVE-2012-2825: libxslt invalid read crash
Status: RESOLVED FIXED
Alias: CVE-2012-2825
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2012-07-26
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp1:48070 maint:...
Keywords:
Depends on:
Blocks:
 
Reported: 2012-06-28 08:36 UTC by Ludwig Nussel
Modified: 2013-11-21 07:43 UTC (History)
4 users (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
libxslt-CVE-2012-2825-2.patch (533 bytes, patch)
2013-11-05 11:05 UTC, Marcus Meissner
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Ludwig Nussel 2012-06-28 08:36:35 UTC
Your friendly security team received the following report via oss-security.
Please respond ASAP.
The issue is public.

======================================================
Name: CVE-2012-2825

The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.


Reference: CONFIRM: http://googlechromereleases.blogspot.com/2012/06/stable-channel-update_26.html
Reference: CONFIRM: http://code.google.com/p/chromium/issues/detail?id=127417


git commit referring to the bug report:
http://git.chromium.org/gitweb/?p=chromium/src.git;a=commitdiff;h=bb7bfb81c158268fb242292b7e0fbd2d3b933d09
Comment 1 Vítězslav Čížek 2012-06-28 12:40:53 UTC
Packages for SLE submitted.
Comment 2 Swamp Workflow Management 2012-06-28 12:58:03 UTC
The SWAMPID for this issue is 48068.
This issue was rated as low.
Please submit fixed packages until 2012-07-26.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 3 Swamp Workflow Management 2012-06-28 22:00:23 UTC
bugbot adjusting priority
Comment 4 Vítězslav Čížek 2012-07-09 13:59:15 UTC
openSUSE packages submitted as well.
Comment 7 Swamp Workflow Management 2012-07-17 09:08:38 UTC
openSUSE-SU-2012:0883-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 769182
CVE References: CVE-2012-2825
Sources used:
openSUSE 12.1 (src):    libxslt-1.1.26-15.8.1, libxslt-python-1.1.26-15.8.1
openSUSE 11.4 (src):    libxslt-1.1.26-3.14.1
Comment 8 Sebastian Krahmer 2012-07-23 08:50:34 UTC
done
Comment 9 Swamp Workflow Management 2012-07-23 12:38:05 UTC
Update released for: libxslt, libxslt-32bit, libxslt-debuginfo, libxslt-debuginfo-32bit, libxslt-debuginfo-x86, libxslt-debugsource, libxslt-devel, libxslt-devel-32bit, libxslt-x86
Products:
SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-DESKTOP 11-SP1-FOR-SP2 (i386, x86_64)
SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SDK 11-SP1-FOR-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1-FOR-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
SLES4VMWARE 11-SP1 (i386, x86_64)
Comment 10 Swamp Workflow Management 2012-07-23 13:08:42 UTC
Update released for: libxslt, libxslt-devel
Products:
SUSE-CORE 9-SP3-TERADATA (x86_64)
Comment 11 Swamp Workflow Management 2012-07-23 13:09:02 UTC
Update released for: libxslt, libxslt-32bit, libxslt-debuginfo, libxslt-devel, libxslt-devel-32bit
Products:
SLE-SERVER 10-SP3-TERADATA (x86_64)
Comment 12 Swamp Workflow Management 2012-07-23 13:59:43 UTC
Update released for: libxslt, libxslt-32bit, libxslt-64bit, libxslt-debuginfo, libxslt-devel, libxslt-devel-32bit, libxslt-devel-64bit, libxslt-x86
Products:
SLE-DESKTOP 10-SP4 (i386, x86_64)
SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Comment 13 Bernhard Wiedemann 2012-08-02 13:00:39 UTC
This is an autogenerated message for OBS integration:
This bug (769182) was mentioned in
https://build.opensuse.org/request/show/129669 Evergreen:11.2 / libxslt
Comment 14 Bernhard Wiedemann 2012-08-07 08:00:38 UTC
This is an autogenerated message for OBS integration:
This bug (769182) was mentioned in
https://build.opensuse.org/request/show/130286 Evergreen:11.2 / libxslt
Comment 16 Marcus Meissner 2013-11-05 11:05:29 UTC
Created attachment 566149 [details]
libxslt-CVE-2012-2825-2.patch

incremental patch using one more check also found in mainline libxslt.
Comment 18 Swamp Workflow Management 2013-11-11 15:55:05 UTC
Update released for: libxslt, libxslt-32bit, libxslt-debuginfo, libxslt-devel, libxslt-devel-32bit, libxslt-python, libxslt-python-debuginfo
Products:
SLE-SERVER 10-SP3-LTSS (i386, s390x, x86_64)
Comment 19 Marcus Meissner 2013-11-21 07:43:09 UTC
released