commit | 8ea80f29ea5fdf383ee3ae59ce35e55421a339f8 | [log] [tgz] |
---|---|---|
author | Brian C. Young <bcyoung@google.com> | Mon Apr 03 12:39:04 2017 -0700 |
committer | gitbuildkicker <android-build@google.com> | Mon Apr 17 16:24:07 2017 -0700 |
tree | 4429dedea0c3e78570da6c646ed5b55e55e1771c | |
parent | ff20cd797822dba8569ee518c44e6864d6b4ebfa [diff] |
DO NOT MERGE: Disallow namespace nodes in XPointer ranges Namespace nodes must be copied to avoid use-after-free errors. But they don't necessarily have a physical representation in a document, so simply disallow them in XPointer ranges. Found with afl-fuzz. Fixes CVE-2016-4658. Bug: 36554207 Change-Id: Ie570c4a53ae8ca82ed4ca19701ab7d8ba9b0468f (cherry picked from commit cde4b40a9c17aec816c6b2577250fff9354a6f3c)