﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
7793	libxml2 Security Issues	Douglas R. Reno	Douglas R. Reno	"As reported on the [oss-security] mailing list today:

'''CVE-2016-3627'''

https://bugzilla.gnome.org/show_bug.cgi?id=765207

{{{
The functions xmlParserEntityCheck() and xmlParseAttValueComplex() used
to call
xmlStringDecodeEntities() in a recursive context without incrementing the
'depth' counter in the parser context. Because of that omission, the parser
failed to detect attribute recursions in certain documents before
running out
of stack space.
}}}

'''CVE-2016-3705'''

https://bugzilla.gnome.org/show_bug.cgi?id=762100


{{{
Subject: [PATCH] xmlStringGetNodeList: limit the function to 1024 recursions
 to avoid CVE-2016-3627
}}}

I can happily create a patch to fix these for both books, unless there is any objection. Should be done before Friday.

I can't attach a link to the mailing list entry from my current location, but I should be able to add it later."	enhancement	closed	high	7.10	BOOK	SVN	medium	fixed		
