| Summary: | expat new security issues CVE-2012-1147, CVE-2012-1148, CVE-2012-0876 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, guillomovitch, mageia, sysadmin-bugs, tmb |
| Version: | 1 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://sourceforge.net/projects/expat/files/expat/2.1.0/ | ||
| Whiteboard: | |||
| Source RPM: | expat-2.0.1-14.mga1.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2012-03-27 23:17:06 CEST
David Walser
2012-03-27 23:18:51 CEST
CC:
(none) =>
mageia Here is the patch for CVE-2012-1147: http://sourceforge.net/tracker/download.php?group_id=10127&atid=110127&file_id=350362&aid=2895533 Reference: http://sourceforge.net/tracker/?func=detail&atid=110127&aid=2895533&group_id=10127
David Walser
2012-03-27 23:28:09 CEST
Blocks:
(none) =>
5046
Guillaume Rousse
2012-03-28 21:57:17 CEST
Status:
NEW =>
ASSIGNED 2.1.0 version submitted for cauldron. expat-2.0.1-14.1.mga submitted for updates_testing. Did the Cauldron update get blocked by the version freeze? Oh, I see. Freeze push requested. Advisory ======================== Updated expat packages fix security vulnerabilities: A memory leak and a hash table collision flaw in expat could cause denial of service (DoS) attacks (CVE-2012-0876, CVE-2012-1148). A resource leak was caused by file descriptors not being closed in readfilemap.c, which could also cause a denial of service (CVE-2012-1147). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0876 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1147 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1148 http://sourceforge.net/projects/expat/files/expat/2.1.0/ http://www.net-security.org/vuln.php?id=16267 http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:041 ======================== Updated packages in core/updates_testing: ======================== expat-2.0.1-14.1.mga1 libexpat1-2.0.1-14.1.mga1 libexpat1-devel-2.0.1-14.1.mga1 from expat-2.0.1-14.1.mga1.src.rpm Assignee:
guillomovitch =>
qa-bugs
David Walser
2012-03-29 23:23:09 CEST
Blocks:
5046 =>
(none) Testing complete on i586 for the srpm expat-2.0.1-14.1.mga1.src.rpm No POC, so just testing that it works ... $ xmlwf /etc/xml/catalog $ xmlwf /etc/passwd /etc/passwd:1:16: not well-formed (invalid token) CC:
(none) =>
davidwhodgins tested ok x86_64 Advisory in comment 6 Could sysadmin please push from core/updates_testing to core/updates Thanks Keywords:
(none) =>
validated_update Update pushed Status:
ASSIGNED =>
RESOLVED |