An integer overflow, leading to heap-based buffer overflow was found in the way libxml, XML files manipulation library, processed certain XPath expressions. A remote attacker could provide a specially-crafted XML file, which once opened in an application linked against libxml would cause that application to crash, or, potentially, execute arbitrary code with the privileges of the user running the application. References: [1] http://scarybeastsecurity.blogspot.com/2011/05/libxml-vulnerability-and-interesting.html [2] http://www.openwall.com/lists/oss-security/2011/05/31/5 [3] http://www.openwall.com/lists/oss-security/2011/05/31/8 Upstream patch: [4] http://git.gnome.org/browse/libxml2/commit/?id=d7958b21e7f8c447a26bb2436f08402b2c308be4
This issue affects the versions of the libxml2 package, as shipped with Red Hat Enterprise Linux 4, 5, and 6. -- This issue affects the versions of the libxml and libxml2 package, as shipped with Fedora release of 13, 14 and 15. Please schedule an update.
Created libxml2 tracking bugs for this issue Affects: fedora-all [bug 709750]
Created libxml tracking bugs for this issue Affects: fedora-all [bug 709751]
(In reply to comment #3) > Created libxml tracking bugs for this issue > > Affects: fedora-all [bug 709751] Note: In libxml F-* package, the relevant affected function is (a/xpath.c): 386 /** 387 * xmlXPathNodeSetAdd: 388 * @cur: the initial node set 389 * @val: a new xmlNodePtr 390 * 391 * add a new xmlNodePtr ot an existing NodeSet 392 */ 393 void 394 xmlXPathNodeSetAdd(xmlNodeSetPtr cur, xmlNodePtr val) { The rest functions from the patch are not present there.
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2011:1749 https://rhn.redhat.com/errata/RHSA-2011-1749.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2012:0017 https://rhn.redhat.com/errata/RHSA-2012-0017.html
Statement: (none)
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0217 https://rhn.redhat.com/errata/RHSA-2013-0217.html