Bug 1388777 (CVE-2016-4738)

Summary: CVE-2016-4738 libxslt: Heap overread due to an empty decimal-separator
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: apevec, ayoung, bhu, carnil, chrisw, cvsbot-xmlrpc, erik-fedora, esammons, gmollett, iboverma, jross, jschluet, kbasil, lhh, lpeer, markmc, matt, mcressma, mrg-program-list, rbryant, rhos-maint, rhs-bugs, rjones, sardella, sclewis, sgirijan, sisharma, smohan, ssaha, storage-qa-internal, tdecacqu, vbellur, veillard, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-02-09 13:41:14 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1388779, 1388780, 1388781    
Bug Blocks: 1388784    

Description Andrej Nemec 2016-10-26 07:50:45 UTC
A heap overread vulnerability was found in xsltFormatNumberConversion function in libxslt. An empty decimal-separator could cause a heap overread. This can be exploited to leak a couple of bytes after the buffer that holds the pattern string.

Upstream patch:

https://git.gnome.org/browse/libxslt/commit/?id=eb1030de31165b68487f288308f9d1810fed6880

Comment 1 Andrej Nemec 2016-10-26 07:56:24 UTC
Created libxslt tracking bugs for this issue:

Affects: fedora-all [bug 1388779]

Comment 2 Andrej Nemec 2016-10-26 07:56:44 UTC
Created mingw-libxslt tracking bugs for this issue:

Affects: fedora-all [bug 1388780]
Affects: epel-7 [bug 1388781]

Comment 4 Huzaifa S. Sidhpurwala 2016-10-31 08:50:02 UTC
This issue was initially filed as chromium bug at:

https://bugs.chromium.org/p/chromium/issues/detail?id=619006