[Bug 1216112] CVE-2015-3451 perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.redhat.com/show_bug.cgi?id=1216112

Kurt Seifried <kseifried@xxxxxxxxxx> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
         Whiteboard|impact=low,public=20150423, |impact=low,public=20150423,
                   |reported=20150423,source=re |reported=20150423,source=re
                   |searcher,cvss2=2.6/AV:N/AC: |searcher,cvss2=2.6/AV:N/AC:
                   |H/Au:N/C:P/I:N/A:N,fedora-a |H/Au:N/C:P/I:N/A:N,fedora-a
                   |ll/perl-XML-LibXML=affected |ll/perl-XML-LibXML=affected
                   |,rhel-5/perl-XML-LibXML=new |,rhel-5/perl-XML-LibXML=won
                   |,rhel-6/perl-XML-LibXML=aff |tfix,rhel-6/perl-XML-LibXML
                   |ected,rhel-7/perl-XML-LibXM |=wontfix,rhel-7/perl-XML-Li
                   |L=affected                  |bXML=wontfix



--- Comment #3 from Kurt Seifried <kseifried@xxxxxxxxxx> ---
Mitigations:

This issue only affects programs using this program in forms such as:

$parser = XML::LibXML->new

or 

$XML_DOC = $parser->load_xml

if you use the form:

$XML_DOC = XML::LibXML->load_xml

this vulnerability will not be exposed.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
--
Fedora Extras Perl SIG
http://www.fedoraproject.org/wiki/Extras/SIGs/Perl
perl-devel mailing list
perl-devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/perl-devel




[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Legacy Announce]     [Fedora PHP Devel]     [Kernel Devel]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Big List of Linux Books]     [Gimp]     [Yosemite Information]
  Powered by Linux