Bug 8609

Summary: expat 2.1.0 has open CVE
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Elena Reshetova <elena.reshetova>
Component: coreAssignee: Armin Kuster <akuster>
Status: VERIFIED WONTFIX QA Contact: Alexandru Georgescu <alexandru.c.georgescu>
Severity: normal    
Priority: Medium+ CC: alexandru.c.georgescu, bluelightning, bogdanx.a.voiculescu, meta.mr.watcher, meta.watcher, sona.sarmadi
Version: unspecified   
Target Milestone: 2.0   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Elena Reshetova 2015-10-29 12:15:09 UTC
expat 2.1.0 has open CVE-2013-0340
Comment 1 Paul Eggleton 2015-10-29 14:11:48 UTC
Is there actually anything to be done about this CVE? From what I can tell the general consensus was to assign CVEs for applications that use it that are vulnerable and do nothing specifically about this CVE itself:

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0340
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0340
http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-0340.html
Comment 2 Paul Eggleton 2015-10-29 15:05:10 UTC
Marking as NEEDINFO as per above comment.
Comment 3 Armin Kuster 2015-10-29 15:45:26 UTC
The CVSS score on this is medium.


this issue is on the App developer not expact 2.1.0



Applications linked with expat can mitigate this issue, by calling the XML_SetEntityDeclHandler() function with the name of an alternative function that can handle entities more safely.

Since API levels mitigations are in place, closing this as wontfix.
Comment 4 Alexandru Georgescu 2015-11-03 08:27:59 UTC
Verified as per above comments.