Bug 556415 - Regression in fix for CVE-2009-3560 [rhel-5]
Summary: Regression in fix for CVE-2009-3560 [rhel-5]
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: expat
Version: 5.0
Hardware: All
OS: Linux
urgent
medium
Target Milestone: rc
: ---
Assignee: Joe Orton
QA Contact: BaseOS QE - Apps
URL:
Whiteboard:
: 573035 (view as bug list)
Depends On:
Blocks: 556422 556424 556427 618744
TreeView+ depends on / blocked
 
Reported: 2010-01-18 10:48 UTC by Joe Orton
Modified: 2018-11-14 17:24 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 556422 556427 (view as bug list)
Environment:
Last Closed: 2013-09-23 11:18:16 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Joe Orton 2010-01-18 10:48:18 UTC
Description:
The fix for CVE-2009-3560 caused a regression.

Parsing some external DTD definitions now fails.

http://mail.libexpat.org/pipermail/expat-discuss/2009-December/002646.html

Version:
expat-1.95.8-8.3.el5_4.2

Comment 5 Jerry Uanino 2010-02-18 13:00:54 UTC
I have a fairly large deployment of redhat systems waiting on this as well.  I haven't called  this into RedHat as I see the public bug already matches what I would call in.

Comment 7 Joe Orton 2010-02-18 17:09:42 UTC
Peter: I do not think there is a bug in XML::Parser here that needs to be reported upstream.  With the fix for the regression applied, the test suite does pass again.

Comment 8 Peter Edwards 2010-02-18 17:36:00 UTC
Joe: You are correct that a bug in XML::Parser does not need to be reported upstream.  I attempted to make the rt.cpan.org ticket entry I created:

  https://rt.cpan.org/Ticket/Display.html?id=54747

a pointer to this bug, and not a bug report in itself.

Comment 9 Joe Orton 2010-03-17 14:07:32 UTC
*** Bug 573035 has been marked as a duplicate of this bug. ***

Comment 10 Tony Howat 2010-05-27 11:27:22 UTC
I'm having the same problems here - this is critical for me, I have large applications built around Frontier::Daemon which relies on CPAN XML::Parser. 

Any progress?

Comment 14 lindahl 2010-07-01 23:17:19 UTC
With RHEL 5.5, the previous (working) version is no longer easily available with "yum downgrade".


Note You need to log in before you can comment on or make changes to this bug.