| Summary: | expat 2.1.0 has open CVE | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Elena Reshetova <elena.reshetova> |
| Component: | core | Assignee: | Armin Kuster <akuster> |
| Status: | VERIFIED WONTFIX | QA Contact: | Alexandru Georgescu <alexandru.c.georgescu> |
| Severity: | normal | ||
| Priority: | Medium+ | CC: | alexandru.c.georgescu, bluelightning, bogdanx.a.voiculescu, meta.mr.watcher, meta.watcher, sona.sarmadi |
| Version: | unspecified | ||
| Target Milestone: | 2.0 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Elena Reshetova
2015-10-29 12:15:09 UTC
Is there actually anything to be done about this CVE? From what I can tell the general consensus was to assign CVEs for applications that use it that are vulnerable and do nothing specifically about this CVE itself: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0340 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0340 http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-0340.html Marking as NEEDINFO as per above comment. The CVSS score on this is medium. this issue is on the App developer not expact 2.1.0 Applications linked with expat can mitigate this issue, by calling the XML_SetEntityDeclHandler() function with the name of an alternative function that can handle entities more safely. Since API levels mitigations are in place, closing this as wontfix. Verified as per above comments. |