Bug 139092

Summary: CAN-2004-0110 multiple buffer overflows (CAN-2004-0989)
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: libxmlAssignee: Daniel Veillard <veillard>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 3CC: marius.andreiana, mattdm
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20040824
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-08-20 06:43:11 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 430644, 430645    

Description Josh Bressers 2004-11-12 21:11:29 UTC
We missed these buffer overflows in libxml, which we fixed in libxml2.

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0110
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0989

These issues also affect FC2

Comment 1 Daniel Veillard 2004-11-12 21:58:03 UTC
Fixed with release 2.6.15 (and 2.6.16-3 yesterday),

Daniel

Comment 2 Josh Bressers 2004-11-12 22:07:35 UTC
Right, this issue is for libxml-1.8.17 though, not libxml2.

Comment 3 Josh Bressers 2004-11-12 22:20:23 UTC
To clarify this (I've confused a few people).

We ship libxml2 and libxml1.  We applied these fixes to libxml2 and released
updates.

We did not apply these to libxml1.

Comment 4 Josh Bressers 2004-11-12 22:32:59 UTC
Testing comment.

Comment 5 Daniel Veillard 2004-11-17 16:38:22 UTC
The same fix for 139090 applies directly to FC2 and FC3 version
of libxml, as a result I pushed:
  - libxml-1_8_17-10_1_2  to dist-fc2-updates-candidate
  - libxml-1_8_17-12      to dist-fc3-updates-candidate

I will try to get them approved for the push, and will send an 
errata mail once done.

Daniel

Comment 6 Matthew Miller 2004-12-02 18:06:25 UTC
Was there ever an update annoucement mail for this? The package is in
the updates area, but I don't think I ever got a message and can't
find one in the fedora-announce-list archives....

Comment 7 Marius Andreiana 2005-08-20 06:43:11 UTC
Closing as updates are out.