[xml/sgml-pkgs] Bug#805146: libxml2: Buffer overead with HTML parser in push mode in xmlSAX2TextNode, causes segfault when compiled with ASAN

Salvatore Bonaccorso carnil at debian.org
Sun Nov 15 10:10:38 UTC 2015


Source: libxml2
Version: 2.9.2+zdfsg1-4
Severity: normal
Tags: security upstream
Forwarded: https://bugzilla.gnome.org/show_bug.cgi?id=756372

Hi,

>From https://bugzilla.redhat.com/show_bug.cgi?id=1281950:
> Stack-based buffer overread vulnerability with HTML parser in push
> mode in xmlSAX2TextNode causing segmentation fault when compiled
> with ASAN.

Upstream bug: https://bugzilla.gnome.org/show_bug.cgi?id=756372 but
there are several interations of the patch so far.

Regards,
Salvatore



More information about the debian-xml-sgml-pkgs mailing list