Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1149084 - (CVE-2014-3660) CVE-2014-3660 libxml2: denial of service via recursive entity expansion
CVE-2014-3660 libxml2: denial of service via recursive entity expansion
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20141016,repor...
: Security
Depends On: 1149085 1149086 1149087 1149088 1161841
Blocks: 1149089
  Show dependency treegraph
 
Reported: 2014-10-03 04:05 EDT by David Jorm
Modified: 2015-11-25 05:14 EST (History)
11 users (show)

See Also:
Fixed In Version: libxml2 2.9.2
Doc Type: Bug Fix
Doc Text:
A denial of service flaw was found in libxml2, a library providing support to read, modify and write XML and HTML files. A remote attacker could provide a specially crafted XML file that, when processed by an application using libxml2, would lead to excessive CPU consumption (denial of service) based on excessive entity substitutions, even if entity substitution was disabled, which is the parser default behavior.
Story Points: ---
Clone Of:
: 1161841 (view as bug list)
Environment:
Last Closed: 2014-11-20 14:09:53 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Proposed upstream patch (4.29 KB, patch)
2014-10-07 01:26 EDT, Huzaifa S. Sidhpurwala
no flags Details | Diff
Patch for RHEL-7 (4.56 KB, patch)
2014-10-12 21:53 EDT, Daniel Veillard
no flags Details | Diff
Patch for RHEL-6 (4.56 KB, patch)
2014-10-12 22:56 EDT, Daniel Veillard
no flags Details | Diff
Patch for RHEL-5 (3.82 KB, patch)
2014-10-12 22:58 EDT, Daniel Veillard
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1655 normal SHIPPED_LIVE Moderate: libxml2 security update 2014-10-16 17:49:06 EDT
Red Hat Product Errata RHSA-2014:1885 normal SHIPPED_LIVE Moderate: libxml2 security update 2014-11-20 18:51:48 EST

  None (edit)
Description David Jorm 2014-10-03 04:05:58 EDT
IssueDescription:

A denial of service flaw was found in libxml2, a library providing support to read, modify and write XML and HTML files. A remote attacker could provide a specially crafted XML file that, when processed by an application using libxml2, would lead to excessive CPU consumption (denial of service) based on excessive entity substitutions, even if entity substitution was disabled, which is the parser default behavior.
Comment 3 Huzaifa S. Sidhpurwala 2014-10-07 01:26:29 EDT
Created attachment 944444 [details]
Proposed upstream patch
Comment 4 Daniel Veillard 2014-10-12 21:53:07 EDT
Created attachment 946196 [details]
Patch for RHEL-7
Comment 5 Daniel Veillard 2014-10-12 22:56:31 EDT
Created attachment 946225 [details]
Patch for RHEL-6
Comment 6 Daniel Veillard 2014-10-12 22:58:07 EDT
Created attachment 946226 [details]
Patch for RHEL-5

This one was actually quite harder to come by, the backport required intimate knowledge of library internals.
Comment 8 errata-xmlrpc 2014-10-16 13:49:22 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7
  Red Hat Enterprise Linux 6

Via RHSA-2014:1655 https://rhn.redhat.com/errata/RHSA-2014-1655.html
Comment 9 Fedora Update System 2014-10-18 12:58:16 EDT
libxml2-2.9.1-3.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 11 Finke Lamein 2014-10-23 03:44:52 EDT
Just wondering, will the RHEL5 patch hit the repositories soon?
Comment 13 Fedora Update System 2014-11-01 13:15:28 EDT
libxml2-2.9.1-6.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 15 errata-xmlrpc 2014-11-20 13:52:22 EST
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 5

Via RHSA-2014:1885 https://rhn.redhat.com/errata/RHSA-2014-1885.html
Comment 16 Fedora Update System 2014-11-22 07:42:33 EST
libxml2-2.9.1-2.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.