Bug 954429 (CVE-2015-8035) - VUL-1: CVE-2015-8035: libxml2: DoS when parsing specially crafted XML document if XZ support is enabled
Summary: VUL-1: CVE-2015-8035: libxml2: DoS when parsing specially crafted XML documen...
Status: RESOLVED FIXED
Alias: CVE-2015-8035
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Deadline: 2016-01-22
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/158471/
Whiteboard: CVSSv2:RedHat:CVE-2015-8035:4.3:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-11-10 10:52 UTC by Sebastian Krahmer
Modified: 2016-06-14 22:00 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
upstream patches (6.00 KB, application/x-tar)
2015-11-20 13:36 UTC, Kristyna Streitova
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2015-11-10 10:52:24 UTC
Quoting from RH BZ:

"A vulnerability in libxml2 when parsing specially crafted XML document if XZ support is enabled causing DoS of application was found."

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1277146
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8035
http://seclists.org/oss-sec/2015/q4/208
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8035.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8035
Comment 3 Swamp Workflow Management 2015-11-10 23:00:56 UTC
bugbot adjusting priority
Comment 6 Kristyna Streitova 2015-11-20 13:36:55 UTC
Created attachment 656787 [details]
upstream patches

Attaching upstream patches:

libxml2-2.9.2-DoS_with_xz_support.patch
- https://git.gnome.org/browse/libxml2/commit/?id=f0709e3ca8f8947f2d91ed34e92e38a4c23eae63

libxml2-2.9.2-reenable_xz_support.patch
- https://git.gnome.org/browse/libxml2/commit/?id=18b8988511b0954272cac4d6c3e6724f9dbf6e0a
- needed for Factory only
Comment 7 Bernhard Wiedemann 2015-11-26 09:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (954429) was mentioned in
https://build.opensuse.org/request/show/346333 Factory / libxml2
Comment 8 SMASH SMASH 2015-11-30 12:16:27 UTC
An update workflow for this issue was started.

This issue was rated as "low".
Please submit fixed packages until "Dec. 14, 2015".

When done, reassign the bug to "security-team@suse.de".
/update/121058/.
Comment 11 Bernhard Wiedemann 2015-12-17 14:00:35 UTC
This is an autogenerated message for OBS integration:
This bug (954429) was mentioned in
https://build.opensuse.org/request/show/349390 13.2+13.1 / libxml2
Comment 13 Swamp Workflow Management 2015-12-27 00:13:34 UTC
openSUSE-SU-2015:2372-1: An update that fixes 14 vulnerabilities is now available.

Category: security (moderate)
Bug References: 928193,951734,951735,954429,956018,956021,956260,957105,957106,957107,957109,957110
CVE References: CVE-2014-0191,CVE-2014-3660,CVE-2015-1819,CVE-2015-5312,CVE-2015-7497,CVE-2015-7498,CVE-2015-7499,CVE-2015-7500,CVE-2015-7941,CVE-2015-7942,CVE-2015-8035,CVE-2015-8241,CVE-2015-8242,CVE-2015-8317
Sources used:
openSUSE 13.2 (src):    libxml2-2.9.3-7.4.1, python-libxml2-2.9.3-7.4.1
openSUSE 13.1 (src):    libxml2-2.9.3-2.19.1, python-libxml2-2.9.3-2.19.1
Comment 14 Swamp Workflow Management 2016-01-07 16:13:29 UTC
SUSE-SU-2016:0049-1: An update that fixes 12 vulnerabilities is now available.

Category: security (moderate)
Bug References: 928193,951734,951735,954429,956018,956021,956260,957105,957106,957107,957109,957110
CVE References: CVE-2015-1819,CVE-2015-5312,CVE-2015-7497,CVE-2015-7498,CVE-2015-7499,CVE-2015-7500,CVE-2015-7941,CVE-2015-7942,CVE-2015-8035,CVE-2015-8241,CVE-2015-8242,CVE-2015-8317
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    libxml2-2.9.1-13.1
SUSE Linux Enterprise Software Development Kit 12 (src):    libxml2-2.9.1-13.1
SUSE Linux Enterprise Server 12-SP1 (src):    libxml2-2.9.1-13.1, python-libxml2-2.9.1-13.1
SUSE Linux Enterprise Server 12 (src):    libxml2-2.9.1-13.1, python-libxml2-2.9.1-13.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    libxml2-2.9.1-13.1, python-libxml2-2.9.1-13.1
SUSE Linux Enterprise Desktop 12 (src):    libxml2-2.9.1-13.1, python-libxml2-2.9.1-13.1
Comment 15 SMASH SMASH 2016-01-08 15:01:46 UTC
An update workflow for this issue was started.

This issue was rated as "low".
Please submit fixed packages until "Jan. 22, 2016".

When done, reassign the bug to "security-team@suse.de".
/update/121235/.
Comment 16 SMASH SMASH 2016-01-08 15:06:32 UTC
An update workflow for this issue was started.

This issue was rated as "low".
Please submit fixed packages until "Jan. 22, 2016".

When done, reassign the bug to "security-team@suse.de".
/update/62418/.
Comment 17 Swamp Workflow Management 2016-01-08 15:08:16 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2016-01-22.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/62418
Comment 18 Andreas Stieger 2016-01-08 15:34:36 UTC
(In reply to Swamp Workflow Management from comment #17)
> An update workflow for this issue was started.
> This issue was rated as moderate.
> Please submit fixed packages until 2016-01-22.
> When done, reassign the bug to security-team@suse.de.
> https://swamp.suse.de/webswamp/wf/62418

Ignore, SLE 10 not affected
Comment 19 Swamp Workflow Management 2016-01-13 17:12:56 UTC
openSUSE-SU-2016:0106-1: An update that fixes 12 vulnerabilities is now available.

Category: security (moderate)
Bug References: 928193,951734,951735,954429,956018,956021,956260,957105,957106,957107,957109,957110
CVE References: CVE-2015-1819,CVE-2015-5312,CVE-2015-7497,CVE-2015-7498,CVE-2015-7499,CVE-2015-7500,CVE-2015-7941,CVE-2015-7942,CVE-2015-8035,CVE-2015-8241,CVE-2015-8242,CVE-2015-8317
Sources used:
openSUSE Leap 42.1 (src):    libxml2-2.9.1-10.1, python-libxml2-2.9.1-10.1
Comment 20 Marcus Meissner 2016-02-10 07:18:40 UTC
i think we released all
Comment 21 Bernhard Wiedemann 2016-03-07 16:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (954429) was mentioned in
https://build.opensuse.org/request/show/367668 Factory / libxml2
Comment 23 Bernhard Wiedemann 2016-06-14 22:00:36 UTC
This is an autogenerated message for OBS integration:
This bug (954429) was mentioned in
https://build.opensuse.org/request/show/400699 42.2 / libxml2