libxml2: CVE-2021-3537

Related Vulnerabilities: CVE-2021-3537  

Debian Bug report logs - #988123
libxml2: CVE-2021-3537

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Thu, 6 May 2021 07:54:01 UTC

Severity: important

Tags: security, upstream

Found in version libxml2/2.9.10+dfsg-6.3

Fixed in version libxml2/2.9.10+dfsg-6.5

Done: Salvatore Bonaccorso <carnil@debian.org>

Forwarded to https://gitlab.gnome.org/GNOME/libxml2/-/issues/243

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org>:
Bug#988123; Package src:libxml2. (Thu, 06 May 2021 07:54:03 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org>. (Thu, 06 May 2021 07:54:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: libxml2: CVE-2021-3537
Date: Thu, 06 May 2021 09:51:15 +0200
Source: libxml2
Version: 2.9.10+dfsg-6.3
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/libxml2/-/issues/243
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerability was published for libxml2.

CVE-2021-3537[0]:
| NULL pointer dereference in valid.c in xmlValidBuildAContentModel

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-3537
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3537
[1] https://gitlab.gnome.org/GNOME/libxml2/-/issues/243
[2] https://gitlab.gnome.org/GNOME/libxml2/-/commit/babe75030c7f64a37826bb3342317134568bef61

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Reply sent to Salvatore Bonaccorso <carnil@debian.org>:
You have taken responsibility. (Thu, 06 May 2021 08:51:07 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Thu, 06 May 2021 08:51:07 GMT) (full text, mbox, link).


Message #10 received at 988123-close@bugs.debian.org (full text, mbox, reply):

From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
To: 988123-close@bugs.debian.org
Subject: Bug#988123: fixed in libxml2 2.9.10+dfsg-6.5
Date: Thu, 06 May 2021 08:48:32 +0000
Source: libxml2
Source-Version: 2.9.10+dfsg-6.5
Done: Salvatore Bonaccorso <carnil@debian.org>

We believe that the bug you reported is fixed in the latest version of
libxml2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 988123@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated libxml2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 06 May 2021 10:28:10 +0200
Source: libxml2
Architecture: source
Version: 2.9.10+dfsg-6.5
Distribution: experimental
Urgency: medium
Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 988123
Changes:
 libxml2 (2.9.10+dfsg-6.5) experimental; urgency=medium
 .
   * Non-maintainer upload.
   * Propagate error in xmlParseElementChildrenContentDeclPriv (CVE-2021-3537)
     (Closes: #988123)
Checksums-Sha1: 
 681a7d5b52667507ba49f4d494fd0174a32973b3 2827 libxml2_2.9.10+dfsg-6.5.dsc
 2bb9ccdd205aac0c3ddce8eddc94de038482e701 31696 libxml2_2.9.10+dfsg-6.5.debian.tar.xz
Checksums-Sha256: 
 ea3449b3a216875905274e6a5c4e83a0f54320195c13454bd06c4c4cba57ba12 2827 libxml2_2.9.10+dfsg-6.5.dsc
 5526177ac1db5c4b9040673329ad05ae408d543a0d101354b505bd288d13fe57 31696 libxml2_2.9.10+dfsg-6.5.debian.tar.xz
Files: 
 1a993e884e816a8570b63df784683486 2827 libs optional libxml2_2.9.10+dfsg-6.5.dsc
 2a9b1881fa6a606e90d31c952dfc9ffb 31696 libs optional libxml2_2.9.10+dfsg-6.5.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmCTqcxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EEWsP/1JQ7UH6s9YM194sF18uyTePS7nt80yl
116SMRmqt+GbsUlvnrVYXmvxG2oGdoJ9mXe/hYc5N5uaeUvoqaBd7jUlhFS9ieBb
MT3RfpOCYLsVH6ICegBig2ZZ+csHOQpBccNvynh+Qse3418RdF4ZendrZ2uPWBp3
dePtR8jKCV8TsB09jUZ5VNspq+goeEuSY4Zi+jjS8O5xJCJvmjjPHByM8eh4Esr3
hEdw/XP1OXpStYmwsoQGlwh4obUt7fRQscITLJ/S22z6Ho83OEzOOe9zoZRx5LVO
8wMJxuKhdpndha++MgMK4UGNzFjxX48hiO0CylG6mZnbyr0XwuRlOPIqY0i6s/RX
ntmhAWb+kzW3IQ/1csEjoizEESHToID8b+CElhsQ9ccfitHW16wxHVoRELRj7zA/
340GV2+MgQ5TYRnepIQ1oLSbT/yUL9OyJhgACKjg8YbNSiGMgVIOHgdt571kEjTi
6wQ37DRolRhN7hmsv/bHJ5TjDrX9Q27DoMopxnSUfONtuyNc7Luke/JNY+ooFglW
YvuOJPlcMHlFJUZQ9mvogooM4szjmCDAmerSioVc0PuefchOPXy1Nih+lDp3gi3Y
2D1bXVv3DMmI33FPZDFxskZQsZjGSDzkiPEK+z98RHu1xpyz6LH7oYJeibdBmMxU
AbaCpmBHti0p
=AU8/
-----END PGP SIGNATURE-----




Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri May 7 08:08:03 2021; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.