Bug 8711

Summary: libxml2: Upgrade to 2.9.3 to address several out of bounds reads in libxml2
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Sona Sarmadi <sona.sarmadi>
Component: coreAssignee: Joshua Lock <joshuagloe>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: akuster, meta.mr.watcher, meta.watcher, richard.purdie
Version: unspecified   
Target Milestone: 1.8.2   
Hardware: All   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Sona Sarmadi 2015-11-23 12:24:14 UTC
There are some CVEs in libxml2 which has not been addressed in our branches (master, jethro, fido, dizzy). I suggest to upgrade libxml2 version in master and all maintained brances to address all these vulnerabilities. Looking at the log, it seems that 2.9.3 is mainely CVE fixes and some minor changes. Any comment on this?


https://git.gnome.org/browse/libxml2/log/

v2.9.3
CVE-2015-8242
CVE-2015-7500
CVE-2015-7499-1
CVE-2015-7499-2
CVE-2015-5312
CVE-2015-7498
CVE-2015-7497
CVE-2015-7942-2
CVE-2015-1819
CVE-2015-7941_2
CVE-2015-7941_1
CVE-2015-7942
CVE-2015-8035

v2.9.2
CVE-2014-3660
v2.9.2-rc2
v2.9.2-rc1
CVE-2013-2877
CVE-2014-0191
v2.9.1
Comment 1 Ross Burton 2015-11-25 21:48:18 UTC
A 2.9.3 upgrade for master is good but for jethro you'll have to convince the jethro maintainer (Robert Yang) that an upgrade is safer than a number of patches.
Comment 2 Armin Kuster 2015-12-01 15:07:28 UTC
some of these have been or are in the middle of being addressed by bug 8641
Comment 3 Armin Kuster 2015-12-01 15:14:30 UTC
there are more than just CVE fixes in this update.

Also, IMHO, not all security issues need to be fixed if the are low enough.
Comment 4 Sona Sarmadi 2015-12-02 06:46:10 UTC
Ok, we just upgrade master and backport individual CVEs in all maintained branches which we believe are important.
Comment 5 Armin Kuster 2015-12-02 16:30:14 UTC
(In reply to comment #4)
> Ok, we just upgrade master and backport individual CVEs in all maintained
> branches which we believe are important.

From an OSV point of view, we have different matrix to determine which CVE's get fixed.

For OE/Yocto project, there may be a different set of standards.
Comment 6 Armin Kuster 2015-12-02 17:21:51 UTC
(In reply to comment #4)
> Ok, we just upgrade master and backport individual CVEs in all maintained
> branches which we believe are important.

By 'we', do you mean the community?
Comment 7 Armin Kuster 2015-12-03 03:35:42 UTC
Looks like master is taken care of.

http://cgit.openembedded.org/openembedded-core/commit/?id=88e68f25e1756988692108d4c15dfa8efc94e5e5
Comment 8 Sona Sarmadi 2015-12-03 07:19:20 UTC
Yes Armin, I mean The Yocto Project Community. 

> From an OSV point of view, we have different matrix to determine which CVE's
get fixed.

What do you mean by “OSV”?

> For OE/Yocto project, there may be a different set of standards.

Do you think it would be better that The Yocto Project have clear process of which CVEs should get fixed?  Maybe we should add this info to Yocto security wiki (as a guideline)?  

We can use NVD scoring (ex: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3660) and have goal to backport all CVS’s scored higher than 5.0 at least in those packages which are widely used. 

For CVEs which are not yet in NVD’s data base, we can use other data base such as:  http://www.cvedetails.com/
Comment 9 Armin Kuster 2015-12-05 21:18:23 UTC
patch set sent for jethro and fido

http://patches.openembedded.org/patch/109267/
Comment 10 Joshua Lock 2016-01-15 15:35:03 UTC
Patches are merged for jethro and pending a merge request for fido.
Comment 11 Joshua Lock 2016-01-26 09:46:12 UTC
Merged to Fido