REDHAT-BUG-1896120: Buffer Overflow
raptorxmlwriterstartelementcommon in raptorxmlwriter.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptorqnameformatasxml).
Reference: https://www.openwall.com/lists/oss-security/2017/06/07/1
Upstream patch: https://github.com/LibreOffice/core/blob/master/external/redland/raptor/0001-Calcualte-max-nspace-declarations-correctly-for-XML-.patch.1
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1896120?
REDHAT-BUG-1896120 is classified as a high severity vulnerability due to the potential for heap-based buffer overflows.
How do I fix REDHAT-BUG-1896120?
To fix REDHAT-BUG-1896120, upgrade to a patched version of the Raptor RDF Syntax Library that addresses the nspace declaration calculation issue.
What causes the vulnerability REDHAT-BUG-1896120?
The vulnerability REDHAT-BUG-1896120 is caused by miscalculation of the maximum namespace declarations for the XML writer in the Raptor RDF Syntax Library.
What are the potential impacts of REDHAT-BUG-1896120?
The potential impacts of REDHAT-BUG-1896120 include application crashes and potential exploitation leading to arbitrary code execution.
Is REDHAT-BUG-1896120 present in all versions of the Raptor RDF Syntax Library?
REDHAT-BUG-1896120 is specifically associated with version 2.0.15 of the Raptor RDF Syntax Library.