GNU bug report logs

#48612 Expat "billion laughs attack" vulnerability (CVE-2013-0340)

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #8 received at 48612@debbugs.gnu.org (full text, mbox, reply):

Received: (at 48612) by debbugs.gnu.org; 23 May 2021 18:40:51 +0000
From debbugs-submit-bounces@debbugs.gnu.org Sun May 23 14:40:51 2021
Received: from localhost ([127.0.0.1]:41750 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1lkt1v-0001wZ-1T
	for submit@debbugs.gnu.org; Sun, 23 May 2021 14:40:51 -0400
Received: from baptiste.telenet-ops.be ([195.130.132.51]:54408)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <maximedevos@telenet.be>) id 1lkt1q-0001wN-Pt
 for 48612@debbugs.gnu.org; Sun, 23 May 2021 14:40:50 -0400
Received: from ptr-bvsjgyjmffd7q9timvx.18120a2.ip6.access.telenet.be
 ([IPv6:2a02:1811:8c09:9d00:aaf1:9810:a0b8:a55d])
 by baptiste.telenet-ops.be with bizsmtp
 id 8Jgk2500H0mfAB401JglJ1; Sun, 23 May 2021 20:40:45 +0200
Message-ID: <29e294edf8ccdb887acd74e5a65c77c2e974aa75.camel@telenet.be>
Subject: Re: bug#48612: Expat "billion laughs attack" vulnerability
 (CVE-2013-0340)
From: Maxime Devos <maximedevos@telenet.be>
To: Marius Bakke <marius@gnu.org>, 48612@debbugs.gnu.org
Date: Sun, 23 May 2021 20:40:29 +0200
In-Reply-To: <87bl91qy68.fsf@gnu.org>
References: <87bl91qy68.fsf@gnu.org>
Content-Type: multipart/signed; micalg="pgp-sha512";
 protocol="application/pgp-signature"; boundary="=-5+5qxg4NogSf9gei5lqQ"
User-Agent: Evolution 3.34.2 
MIME-Version: 1.0
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=telenet.be; s=r21;
 t=1621795245; bh=+jRThxMmU3cVuKewz1J8Q606pcg7nicxXkFheAd8tD8=;
 h=Subject:From:To:Date:In-Reply-To:References;
 b=dY9jRLhd4lQASVgbF5fN6BV+8tAhBJvD4j8ZN5HDabmAd8uMpDCzWE8MKL/F92VVL
 RYn5aMmnnao2TnJYHCnwZ36PR9PkZ7wXrCH1SHKhaCefq10RXh8OdiIYVMwwxqODNF
 9Z4j8ZdNivn4dMs4JTLBitekj7ygWN2Tw+UTBM/t5XwW3gKuOxDmiAiddA6AmfEa0S
 JdGNmZE/VQbfe0jrK8//Wb5HPHTyi61ZWbJQNcDBZMg3eBDgsJRgTHDRzBw9O2/ERM
 yMBMeoQRn9/QQ5XzV+eP4u7U0aVVx+iRiMPpjM5Fmm9ZOnel3zscVhpiIhmvFqHy0R
 O2KZYUuPV5iOA==
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 48612
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
[Message part 1 (text/plain, inline)]
Marius Bakke schreef op zo 23-05-2021 om 17:15 [+0200]:
> Greetings Guix,
> 
> What's old is new again!  Expat 2.4.0 was recently released with a
> fix for a denial of service issue dubbed "billion laughs attack":
> 
>   https://github.com/libexpat/libexpat/blob/R_2_4_0/expat/Changes
>   https://en.wikipedia.org/wiki/Billion_laughs_attack
> 
> Seeing as this vulnerability appears to be eight years old and is
> "merely" a DoS: is it worth fixing on the 'master' branch (and
> re-grafting pretty much everything)?

Since this is ‘merely’ a DoS that does not lead to an exploit, I
would simply upgrade the package on 'core-updates'. However, I don't
run any servers. At worst, an attacker could bring down a computer or
burn CPU cyles but nothing else. Bad, but not an exploit and not worth
a graft in my opinion. If this attack is found to cause an annoyance in
the wild, we can easily add a graft later.

> 
> In any case I've attached a patch that does just that and I'm currently
> using it on my system.  I'm hesitant to push it because of the grafting
> cost and would like others opinion.
> 

I would like others opinion as well.

Greetings,
Maxime.
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 18:34:05 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.