Bugzilla – Bug 981115
VUL-1: CVE-2016-1840: libxml2: heap-buffer-overflow in xmlFAParsePosCharGroup
Last modified: 2016-09-21 03:26:25 UTC
https://git.gnome.org/browse/libxml2/tag/?h=CVE-2016-1840 heap-buffer-overflow in xmlFAParsePosCharGroup https://bugzilla.gnome.org/show_bug.cgi?id=757711 * xmlregexp.c: (xmlFAParseCharRange): Only advance to the next character if there is no error. Advancing to the next character in case of an error while parsing regexp leads to an out of bounds access.
bugbot adjusting priority
Upstream git entry: https://git.gnome.org/browse/libxml2/commit/?h=CVE-2016-1840&id=cbb271655cadeb8dbb258a64701d9a3a0c4835b4
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2016-06-17. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62795
SUSE-SU-2016:1538-1: An update that fixes 15 vulnerabilities is now available. Category: security (important) Bug References: 963963,965283,978395,981040,981041,981108,981109,981111,981112,981114,981115,981548,981549,981550 CVE References: CVE-2015-8806,CVE-2016-1762,CVE-2016-1833,CVE-2016-1834,CVE-2016-1835,CVE-2016-1837,CVE-2016-1838,CVE-2016-1839,CVE-2016-1840,CVE-2016-2073,CVE-2016-3705,CVE-2016-4447,CVE-2016-4448,CVE-2016-4449,CVE-2016-4483 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP1 (src): libxml2-2.9.1-24.1 SUSE Linux Enterprise Software Development Kit 12 (src): libxml2-2.9.1-24.1 SUSE Linux Enterprise Server 12-SP1 (src): libxml2-2.9.1-24.1, python-libxml2-2.9.1-24.1 SUSE Linux Enterprise Server 12 (src): libxml2-2.9.1-24.1, python-libxml2-2.9.1-24.1 SUSE Linux Enterprise Desktop 12-SP1 (src): libxml2-2.9.1-24.1, python-libxml2-2.9.1-24.1 SUSE Linux Enterprise Desktop 12 (src): libxml2-2.9.1-24.1, python-libxml2-2.9.1-24.1
openSUSE-SU-2016:1594-1: An update that solves 12 vulnerabilities and has one errata is now available. Category: security (important) Bug References: 972335,975947,978395,981040,981041,981108,981109,981110,981111,981112,981114,981115,983288 CVE References: CVE-2016-1762,CVE-2016-1833,CVE-2016-1834,CVE-2016-1835,CVE-2016-1836,CVE-2016-1837,CVE-2016-1838,CVE-2016-1839,CVE-2016-1840,CVE-2016-3627,CVE-2016-3705,CVE-2016-4483 Sources used: openSUSE 13.2 (src): libxml2-2.9.4-7.17.1, python-libxml2-2.9.4-7.17.1
openSUSE-SU-2016:1595-1: An update that fixes 15 vulnerabilities is now available. Category: security (important) Bug References: 963963,965283,978395,981040,981041,981108,981109,981111,981112,981114,981115,981548,981549,981550 CVE References: CVE-2015-8806,CVE-2016-1762,CVE-2016-1833,CVE-2016-1834,CVE-2016-1835,CVE-2016-1837,CVE-2016-1838,CVE-2016-1839,CVE-2016-1840,CVE-2016-2073,CVE-2016-3705,CVE-2016-4447,CVE-2016-4448,CVE-2016-4449,CVE-2016-4483 Sources used: openSUSE Leap 42.1 (src): libxml2-2.9.1-19.1, python-libxml2-2.9.1-19.1
SUSE-SU-2016:1604-1: An update that fixes 15 vulnerabilities is now available. Category: security (important) Bug References: 963963,965283,978395,981040,981041,981108,981109,981111,981112,981114,981115,981548,981549,981550 CVE References: CVE-2015-8806,CVE-2016-1762,CVE-2016-1833,CVE-2016-1834,CVE-2016-1835,CVE-2016-1837,CVE-2016-1838,CVE-2016-1839,CVE-2016-1840,CVE-2016-2073,CVE-2016-3705,CVE-2016-4447,CVE-2016-4448,CVE-2016-4449,CVE-2016-4483 Sources used: SUSE OpenStack Cloud 5 (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4 SUSE Manager Proxy 2.1 (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4 SUSE Manager 2.1 (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4 SUSE Linux Enterprise Software Development Kit 11-SP4 (src): libxml2-2.7.6-0.44.1 SUSE Linux Enterprise Server 11-SP4 (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4 SUSE Linux Enterprise Server 11-SP3-LTSS (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4 SUSE Linux Enterprise Server 11-SP2-LTSS (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4 SUSE Linux Enterprise Debuginfo 11-SP4 (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4 SUSE Linux Enterprise Debuginfo 11-SP3 (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4 SUSE Linux Enterprise Debuginfo 11-SP2 (src): libxml2-2.7.6-0.44.1, libxml2-python-2.7.6-0.44.4
all released