commit | b95edfcaccb48cf0e357d3840de56b7228879fbf | [log] [tgz] |
---|---|---|
author | Brian C. Young <bcyoung@google.com> | Mon Apr 03 12:39:04 2017 -0700 |
committer | gitbuildkicker <android-build@google.com> | Mon Apr 24 12:19:35 2017 -0700 |
tree | 4429dedea0c3e78570da6c646ed5b55e55e1771c | |
parent | 14daafe30c13b851bae6ecccd76374e26e4a2db1 [diff] |
DO NOT MERGE: Disallow namespace nodes in XPointer ranges Namespace nodes must be copied to avoid use-after-free errors. But they don't necessarily have a physical representation in a document, so simply disallow them in XPointer ranges. Found with afl-fuzz. Fixes CVE-2016-4658. Bug: 36554207 Change-Id: Ie570c4a53ae8ca82ed4ca19701ab7d8ba9b0468f (cherry picked from commit cde4b40a9c17aec816c6b2577250fff9354a6f3c)