<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>8711</bug_id>
          
          <creation_ts>2015-11-23 12:24:14 +0000</creation_ts>
          <short_desc>libxml2: Upgrade to 2.9.3 to address several out of bounds reads in libxml2</short_desc>
          <delta_ts>2016-01-26 09:46:12 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>1.8.2</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sona Sarmadi">sona.sarmadi</reporter>
          <assigned_to name="Joshua Lock">joshuagloe</assigned_to>
          <cc>akuster</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>richard.purdie</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>56689</commentid>
    <comment_count>0</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-11-23 12:24:14 +0000</bug_when>
    <thetext>There are some CVEs in libxml2 which has not been addressed in our branches (master, jethro, fido, dizzy). I suggest to upgrade libxml2 version in master and all maintained brances to address all these vulnerabilities. Looking at the log, it seems that 2.9.3 is mainely CVE fixes and some minor changes. Any comment on this?


https://git.gnome.org/browse/libxml2/log/

v2.9.3
CVE-2015-8242
CVE-2015-7500
CVE-2015-7499-1
CVE-2015-7499-2
CVE-2015-5312
CVE-2015-7498
CVE-2015-7497
CVE-2015-7942-2
CVE-2015-1819
CVE-2015-7941_2
CVE-2015-7941_1
CVE-2015-7942
CVE-2015-8035

v2.9.2
CVE-2014-3660
v2.9.2-rc2
v2.9.2-rc1
CVE-2013-2877
CVE-2014-0191
v2.9.1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>56791</commentid>
    <comment_count>1</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2015-11-25 21:48:18 +0000</bug_when>
    <thetext>A 2.9.3 upgrade for master is good but for jethro you&apos;ll have to convince the jethro maintainer (Robert Yang) that an upgrade is safer than a number of patches.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>56895</commentid>
    <comment_count>2</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2015-12-01 15:07:28 +0000</bug_when>
    <thetext>some of these have been or are in the middle of being addressed by bug 8641</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>56896</commentid>
    <comment_count>3</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2015-12-01 15:14:30 +0000</bug_when>
    <thetext>there are more than just CVE fixes in this update.

Also, IMHO, not all security issues need to be fixed if the are low enough.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>56925</commentid>
    <comment_count>4</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-12-02 06:46:10 +0000</bug_when>
    <thetext>Ok, we just upgrade master and backport individual CVEs in all maintained branches which we believe are important.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>56950</commentid>
    <comment_count>5</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2015-12-02 16:30:14 +0000</bug_when>
    <thetext>(In reply to comment #4)
&gt; Ok, we just upgrade master and backport individual CVEs in all maintained
&gt; branches which we believe are important.

From an OSV point of view, we have different matrix to determine which CVE&apos;s get fixed.

For OE/Yocto project, there may be a different set of standards.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>56957</commentid>
    <comment_count>6</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2015-12-02 17:21:51 +0000</bug_when>
    <thetext>(In reply to comment #4)
&gt; Ok, we just upgrade master and backport individual CVEs in all maintained
&gt; branches which we believe are important.

By &apos;we&apos;, do you mean the community?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>56973</commentid>
    <comment_count>7</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2015-12-03 03:35:42 +0000</bug_when>
    <thetext>Looks like master is taken care of.

http://cgit.openembedded.org/openembedded-core/commit/?id=88e68f25e1756988692108d4c15dfa8efc94e5e5</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>56974</commentid>
    <comment_count>8</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-12-03 07:19:20 +0000</bug_when>
    <thetext>Yes Armin, I mean The Yocto Project Community. 

&gt; From an OSV point of view, we have different matrix to determine which CVE&apos;s
get fixed.

What do you mean by “OSV”?

&gt; For OE/Yocto project, there may be a different set of standards.

Do you think it would be better that The Yocto Project have clear process of which CVEs should get fixed?  Maybe we should add this info to Yocto security wiki (as a guideline)?  

We can use NVD scoring (ex: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3660) and have goal to backport all CVS’s scored higher than 5.0 at least in those packages which are widely used. 

For CVEs which are not yet in NVD’s data base, we can use other data base such as:  http://www.cvedetails.com/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>57060</commentid>
    <comment_count>9</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2015-12-05 21:18:23 +0000</bug_when>
    <thetext>patch set sent for jethro and fido

http://patches.openembedded.org/patch/109267/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>57867</commentid>
    <comment_count>10</comment_count>
    <who name="Joshua Lock">joshuagloe</who>
    <bug_when>2016-01-15 15:35:03 +0000</bug_when>
    <thetext>Patches are merged for jethro and pending a merge request for fido.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58219</commentid>
    <comment_count>11</comment_count>
    <who name="Joshua Lock">joshuagloe</who>
    <bug_when>2016-01-26 09:46:12 +0000</bug_when>
    <thetext>Merged to Fido</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>