Bug 8609 - expat 2.1.0 has open CVE
Summary: expat 2.1.0 has open CVE
Status: VERIFIED WONTFIX
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 2.0
Assignee: Armin Kuster
QA Contact: Alexandru Georgescu
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2015-10-29 12:15 UTC by Elena Reshetova
Modified: 2015-11-05 10:37 UTC (History)
6 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Elena Reshetova 2015-10-29 12:15:09 UTC
expat 2.1.0 has open CVE-2013-0340
Comment 1 Paul Eggleton 2015-10-29 14:11:48 UTC
Is there actually anything to be done about this CVE? From what I can tell the general consensus was to assign CVEs for applications that use it that are vulnerable and do nothing specifically about this CVE itself:

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0340
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0340
http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-0340.html
Comment 2 Paul Eggleton 2015-10-29 15:05:10 UTC
Marking as NEEDINFO as per above comment.
Comment 3 Armin Kuster 2015-10-29 15:45:26 UTC
The CVSS score on this is medium.


this issue is on the App developer not expact 2.1.0



Applications linked with expat can mitigate this issue, by calling the XML_SetEntityDeclHandler() function with the name of an alternative function that can handle entities more safely.

Since API levels mitigations are in place, closing this as wontfix.
Comment 4 Alexandru Georgescu 2015-11-03 08:27:59 UTC
Verified as per above comments.