Bug 1277146 (CVE-2015-8035)

Summary: CVE-2015-8035 libxml2: DoS caused by incorrect error detection during XZ decompression
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: athmanem, carnil, c.david86, csutherl, dknox, erik-fedora, fedora-mingw, jclere, jdoyle, ktietz, lgao, malmond, mbabacek, mturk, myarboro, ohudlick, rjones, slawomir, twalsh, veillard, weli
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to crash.
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 02:45:04 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1277147, 1277149, 1277150, 1322872, 1595697    
Bug Blocks: 1274223, 1277152, 1318206    
Attachments:
Description Flags
Suggested patch for the issue none

Description Adam Mariš 2015-11-02 13:45:30 UTC
A vulnerability in libxml2 when parsing specially crafted XML document if XZ support is enabled causing DoS of application was found.

CVE request (including reproducer):

http://seclists.org/oss-sec/2015/q4/206

Comment 1 Adam Mariš 2015-11-02 13:46:11 UTC
Created libxml2 tracking bugs for this issue:

Affects: fedora-all [bug 1277147]

Comment 2 Adam Mariš 2015-11-02 13:46:19 UTC
Created mingw-libxml2 tracking bugs for this issue:

Affects: fedora-all [bug 1277149]
Affects: epel-7 [bug 1277150]

Comment 3 Martin Prpič 2015-11-02 14:16:34 UTC
Statement:

This issue did not affect the versions of libxml2 as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include support for LZMA compression support.

Comment 4 Martin Prpič 2015-11-02 14:58:21 UTC
LZMA compression support was introduced in libxml2 in:

2.8.0: May 23 2012
Features: add lzma compression support (Anders F Bjorklund)

Comment 5 Daniel Veillard 2015-11-02 16:45:39 UTC
So lzma support in 2.9.2 seems to be broken that's why Fedora seems not affected.

But the bug is present since all version 2.8.0 onward.
Seems I managed to get a first fix for the issue, I will add as attachment

Daniel

Comment 6 Daniel Veillard 2015-11-02 16:46:28 UTC
Created attachment 1088640 [details]
Suggested patch for the issue

Comment 13 errata-xmlrpc 2016-05-17 16:14:02 UTC
This issue has been addressed in the following products:



Via RHSA-2016:1089 https://rhn.redhat.com/errata/RHSA-2016-1089.html

Comment 14 Matthew Almond 2018-06-26 21:20:30 UTC
Will this bug be addressed in RHEL7.x?

Comment 16 Adam Mariš 2018-06-27 11:56:22 UTC
(In reply to Matthew Almond from comment #14)
> Will this bug be addressed in RHEL7.x?

Thanks for notifying us, this may be fixed in future release.

Comment 17 errata-xmlrpc 2020-03-31 19:33:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:1190 https://access.redhat.com/errata/RHSA-2020:1190