~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2017-9050

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2017-05-18
2
 
Candidate: CVE-2017-9050
3
 
PublicDate: 2017-05-18
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9050
6
 
 http://www.openwall.com/lists/oss-security/2017/05/15/1
7
 
 https://usn.ubuntu.com/usn/usn-3424-1
8
 
 https://usn.ubuntu.com/usn/usn-3424-2
9
 
Description:
10
 
 libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer
11
 
 over-read in the xmlDictAddString function in dict.c. This vulnerability
12
 
 causes programs that use libxml2, such as PHP, to crash. This vulnerability
13
 
 exists because of an incomplete fix for CVE-2016-1839.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
 mdeslaur> probably same issue as CVE-2017-9049
17
 
Bugs:
18
 
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863018
19
 
 https://bugzilla.gnome.org/show_bug.cgi?id=781361
20
 
Priority: medium
21
 
Discovered-by: Marcel Böhme and Van-Thuan Pham
22
 
Assigned-to:
23
 
 
24
 
Patches_libxml2:
25
 
 upstream: https://git.gnome.org/browse/libxml2/commit/?id=e26630548e7d138d2c560844c43820b6767251e3
26
 
upstream_libxml2: released (2.9.4+dfsg1-3.1)
27
 
precise/esm_libxml2: released (2.7.8.dfsg-5.1ubuntu4.18)
28
 
trusty_libxml2: released (2.9.1+dfsg1-3ubuntu4.10)
29
 
vivid/stable-phone-overlay_libxml2: ignored (reached end-of-life)
30
 
vivid/ubuntu-core_libxml2: DNE
31
 
xenial_libxml2: released (2.9.3+dfsg1-1ubuntu0.3)
32
 
yakkety_libxml2: ignored (reached end-of-life)
33
 
zesty_libxml2: released (2.9.4+dfsg1-2.2ubuntu0.1)
34
 
devel_libxml2: not-affected (2.9.4+dfsg1-3.1)