https://bugzilla.redhat.com/show_bug.cgi?id=1274222
Bug ID: 1274222 Summary: libxml2: Out-of-bounds memory access Product: Security Response Component: vulnerability Keywords: Security Severity: low Priority: low Assignee: security-response-team@redhat.com Reporter: amaris@redhat.com CC: athmanem@gmail.com, c.david86@gmail.com, drizt@land.ru, erik-fedora@vanpienbroek.nl, fedora-mingw@lists.fedoraproject.org, ktietz@redhat.com, lfarkas@lfarkas.org, ohudlick@redhat.com, rjones@redhat.com, veillard@redhat.com, weli@redhat.com
An out-of-bounds read vulnerability was found in libxml2 with crafted xml input.
Report can be found here:
https://bugzilla.gnome.org/show_bug.cgi?id=744980#c1
Upstream patches:
https://git.gnome.org/browse/libxml2/commit/?id=a7dfab7411cbf545f359dd3157e5... https://git.gnome.org/browse/libxml2/commit/?id=9b8512337d14c8ddf662fcb98b01...
CVE request:
http://seclists.org/oss-sec/2015/q4/127