oss-sec mailing list archives

Re: CVE-2011-3102 / libxml2


From: Jan Lieskovsky <jlieskov () redhat com>
Date: Tue, 22 May 2012 11:13:53 +0200


Hi Moritz,

On 05/21/2012 10:22 PM, Moritz Muehlenhoff wrote:
Hi,
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3102 points to
http://code.google.com/p/chromium/issues/detail?id=125462, which is
a 404.

http://googlechromereleases.blogspot.de/2012/05/stable-channel-update.html
references Jueri Aedla for the credits. I suppose this is related to this
libxml2 upstream commit:
http://git.gnome.org/browse/libxml2/commit/?id=d8e1faeaa99c7a7c07af01c1c72de352eb590a3e

Yes, we have previously checked with Daniel and he confirmed this one -^ would be
the correct one.

(have updated our bugzilla entry to state it in more exact way:
https://bugzilla.redhat.com/show_bug.cgi?id=822109#c2)


Can anyone of the involved parties at Chrome and Red Hat please confirm?

Without not to leak too much, Daniel also clarified this problem would be
of higher impact / security relevance for Google Chrome instances due the
way they use XPointer functionality. On common Linux libxml2 instances
additional functionality to be involved is needed this to be exploited
in that way as it has been for Google Chrome case.

Hope this helps. Let us know if we can be of any further advice.

Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team


Cheers,
         Moritz


Current thread: