After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 679475 - cve-2012-2807
cve-2012-2807
Status: RESOLVED OBSOLETE
Product: libxml2
Classification: Platform
Component: general
git master
Other Linux
: Normal blocker
: ---
Assigned To: Daniel Veillard
libxml QA maintainers
Depends on:
Blocks:
 
 
Reported: 2012-07-05 22:35 UTC by Michael Gilbert
Modified: 2021-07-05 13:21 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description Michael Gilbert 2012-07-05 22:35:32 UTC
The chrome developers have found another libxml2 issue, which seems to have not been upstreamed yet:
http://security-tracker.debian.org/tracker/CVE-2012-2807

The following commit supposedly corrects the issue:
http://git.chromium.org/gitweb/?p=chromium/src.git;a=patch;h=f183580d61c054f7f6bb35cfe29e1b342390fbebcd

But there are questions about the hard-coded limits and whether they're appropriate:
http://bugs.debian.org/679280
Comment 1 Gaurav 2015-10-20 11:51:45 UTC
The commit link is broken.
Comment 2 Ludovico de Nittis 2017-08-05 20:37:54 UTC
This is an updated link to the submitted chromium patch https://src.chromium.org/viewvc/chrome?revision=143067&view=revision

However two years ago with this commit the patch has been removed https://chromium.googlesource.com/chromium/src/+/8285ba172641308c6d4775cc38d637ceacb0422a
Comment 4 André Klapper 2020-11-15 14:11:29 UTC
(In reply to André Klapper from comment #3)
> Fixed by
> https://gitlab.gnome.org/GNOME/libxml2/commit/
> 459eeb9dc752d5185f57ff6b135027f11981a626 if I interpret
> http://security-tracker.debian.org/tracker/CVE-2012-2807 correctly?

Can someone confirm, please?
Comment 5 GNOME Infrastructure Team 2021-07-05 13:21:56 UTC
GNOME is going to shut down bugzilla.gnome.org in favor of gitlab.gnome.org.
As part of that, we are mass-closing older open tickets in bugzilla.gnome.org
which have not seen updates for a longer time (resources are unfortunately
quite limited so not every ticket can get handled).

If you can still reproduce the situation described in this ticket in a recent
and supported software version, then please follow
  https://wiki.gnome.org/GettingInTouch/BugReportingGuidelines
and create a new ticket at
  https://gitlab.gnome.org/GNOME/libxml2/-/issues/

Thank you for your understanding and your help.