Bug 30646 - libxml2: Two security issues (3.1)
libxml2: Two security issues (3.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 3.0
Other Linux
: P3 normal (vote)
: UCS 3.1-1-errata
Assigned To: Moritz Muehlenhoff
Janek Walkenhorst
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-03-04 16:46 CET by Moritz Muehlenhoff
Modified: 2013-05-22 10:11 CEST (History)
0 users

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Moritz Muehlenhoff univentionstaff 2013-03-04 16:46:02 CET
+++ This bug was initially created as a clone of Bug #30645 +++

+++ This bug was initially created as a clone of Bug #30644 +++

Denial of service when including external entity references (CVE-2013-0338
CVE-2013-0339)
Comment 1 Moritz Muehlenhoff univentionstaff 2013-05-10 13:12:56 CEST
The DSA version has been imported. Test procedure on amd64 was successful. The YAML file has been commited to SVN.
Comment 2 Moritz Muehlenhoff univentionstaff 2013-05-10 14:24:55 CEST
(In reply to comment #1)
> The DSA version has been imported. Test procedure on amd64 was successful. The
> YAML file has been commited to SVN.

Also, the update has been copied to ucs3.1-2
Comment 3 Janek Walkenhorst univentionstaff 2013-05-14 16:46:44 CEST
Tests with i386 successful.

Advisory: version is [0,1] - is this intended? -- except that: OK

Package not in scope ucs_3.1-2
Comment 4 Moritz Muehlenhoff univentionstaff 2013-05-21 12:42:15 CEST
(In reply to comment #3)
> Tests with i386 successful.
> 
> Advisory: version is [0,1] - is this intended? -- except that: OK

Yes, that's intended: libxml is identical in 3.1-0 and 3.1-1, so the files can be made available in both the errata3.1-0 and errata3.1-1 scopes.
 
> Package not in scope ucs_3.1-2

As discussed: They are present, but at the time when you made the check the Packages file hadn't been rebuild (since no build took place for 3.1-2 by then).
Comment 5 Janek Walkenhorst univentionstaff 2013-05-21 15:47:14 CEST
(In reply to comment #4)
> Yes, that's intended: libxml is identical in 3.1-0 and 3.1-1, so the files can
> be made available in both the errata3.1-0 and errata3.1-1 scopes.
OK

> As discussed: They are present, but at the time when you made the check the
> Packages file hadn't been rebuild (since no build took place for 3.1-2 by
> then).
OK
Comment 6 Moritz Muehlenhoff univentionstaff 2013-05-22 10:11:02 CEST
http://errata.univention.de/ucs/3.1/101.html