Bug 980391 (CVE-2015-1283) - VUL-0: CVE-2015-1283: expat: Heap-buffer-overflow in expat
Summary: VUL-0: CVE-2015-1283: expat: Heap-buffer-overflow in expat
Status: RESOLVED FIXED
Alias: CVE-2015-1283
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/385752/
Whiteboard: maint:running:62734:moderate maint:re...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-05-17 16:35 UTC by Kristyna Streitova
Modified: 2023-11-21 16:33 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kristyna Streitova 2016-05-17 16:35:53 UTC
CVE-2015-1283

Description:
============
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.

Affected versions:
==================
- expat 2.1.0 and previous versions
- chrome 43.0.2357.134 and previous versions
  * see bug#939077
  * it has been already fixed for chromium

Expat patches:
==============
https://sourceforge.net/p/expat/code_git/ci/ba0f9c3b40c264b8dd392e02a7a060a8fa54f032

https://sourceforge.net/p/expat/code_git/ci/f0bec73b018caa07d3e75ec8dd967f3785d71bde


References:
===========
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1283
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1283
https://sourceforge.net/p/expat/bugs/528/
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-1283
Comment 2 Bernhard Wiedemann 2016-05-18 13:00:16 UTC
This is an autogenerated message for OBS integration:
This bug (980391) was mentioned in
https://build.opensuse.org/request/show/396617 13.2 / expat
Comment 7 Swamp Workflow Management 2016-05-30 12:09:37 UTC
openSUSE-SU-2016:1441-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 979441,980391
CVE References: CVE-2015-1283,CVE-2016-0718
Sources used:
openSUSE 13.2 (src):    expat-2.1.0-14.3.1
Comment 13 Swamp Workflow Management 2016-06-07 11:08:21 UTC
SUSE-SU-2016:1508-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 979441,980391
CVE References: CVE-2015-1283,CVE-2016-0718
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    expat-2.1.0-17.1
SUSE Linux Enterprise Software Development Kit 12 (src):    expat-2.1.0-17.1
SUSE Linux Enterprise Server 12-SP1 (src):    expat-2.1.0-17.1
SUSE Linux Enterprise Server 12 (src):    expat-2.1.0-17.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    expat-2.1.0-17.1
SUSE Linux Enterprise Desktop 12 (src):    expat-2.1.0-17.1
Comment 14 Swamp Workflow Management 2016-06-07 15:09:10 UTC
SUSE-SU-2016:1512-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 979441,980391
CVE References: CVE-2015-1283,CVE-2016-0718
Sources used:
SUSE Studio Onsite 1.3 (src):    expat-2.0.1-88.38.1
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    expat-2.0.1-88.38.1
SUSE Linux Enterprise Server 11-SP4 (src):    expat-2.0.1-88.38.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    expat-2.0.1-88.38.1
Comment 15 Swamp Workflow Management 2016-06-08 10:08:06 UTC
openSUSE-SU-2016:1523-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 979441,980391
CVE References: CVE-2015-1283,CVE-2016-0718
Sources used:
openSUSE Leap 42.1 (src):    expat-2.1.0-17.1
Comment 16 Marcus Meissner 2016-06-09 14:19:29 UTC
released
Comment 17 Kristyna Streitova 2016-06-16 14:16:03 UTC
The re-fix [1] of the original patch has obtained a CVE number (CVE-2016-4472). See bug 983985.

The re-fix was already applied but CVE is not mentioned in the changelog as it was assigned after this submission. It will be added in the next update.

[1] https://sourceforge.net/p/expat/code_git/ci/f0bec73b018caa07d3e75ec8dd967f3785d71bde