[ubuntu/maverick-security] libxml2 2.7.7.dfsg-4ubuntu0.3 (Accepted)

Jamie Strandboge jamie at ubuntu.com
Thu Jan 19 17:34:10 UTC 2012


libxml2 (2.7.7.dfsg-4ubuntu0.3) maverick-security; urgency=low

  * SECURITY UPDATE: fix off-by-one leading to denial of service
    - encoding.c: adjust calculation of space available
    - 69f04562f75212bfcabecd190ea8b06ace28ece2
    - CVE-2011-0216
  * SECURITY UPDATE: fix double free in XPath evaluation
    - xpath.h, xpath.c: add a mechanism of frame for XPath evaluation when
      entering a function or a scoped evaluation
    - f5048b3e71fc30ad096970b8df6e7af073bae4cb
    - CVE-2011-2821
  * SECURITY UPDATE: fix double free in XPath evaluation
    - xpath.c: fix missing error status in XPath evaluation
    - 1d4526f6f4ec8d18c40e2a09b387652a6c1aa2cd
    - CVE-2011-2834
  * SECURITY UPDATE: fix out of bounds read
    - parser.c: make sure the parser returns when getting a Stop order
    - 77404b8b69bc122d12231807abf1a837d121b551
    - CVE-2011-3905
  * SECURITY UPDATE: fix heap overflow
    - parser.c: fix an allocation error when copying entities
    - 5bd3c061823a8499b27422aee04ea20aae24f03e
    - CVE-2011-3919

Date: Wed, 18 Jan 2012 13:46:22 -0600
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/maverick/+source/libxml2/2.7.7.dfsg-4ubuntu0.3
-------------- next part --------------
Format: 1.8
Date: Wed, 18 Jan 2012 13:46:22 -0600
Source: libxml2
Binary: libxml2 libxml2-utils libxml2-dev libxml2-dbg libxml2-doc python-libxml2 python-libxml2-dbg libxml2-udeb
Architecture: source
Version: 2.7.7.dfsg-4ubuntu0.3
Distribution: maverick-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description: 
 libxml2    - GNOME XML library
 libxml2-dbg - Debugging symbols for the GNOME XML library
 libxml2-dev - Development files for the GNOME XML library
 libxml2-doc - Documentation for the GNOME XML library
 libxml2-udeb - GNOME XML library - minimal runtime (udeb)
 libxml2-utils - XML utilities
 python-libxml2 - Python bindings for the GNOME XML library
 python-libxml2-dbg - Python bindings for the GNOME XML library (debug extension)
Changes: 
 libxml2 (2.7.7.dfsg-4ubuntu0.3) maverick-security; urgency=low
 .
   * SECURITY UPDATE: fix off-by-one leading to denial of service
     - encoding.c: adjust calculation of space available
     - 69f04562f75212bfcabecd190ea8b06ace28ece2
     - CVE-2011-0216
   * SECURITY UPDATE: fix double free in XPath evaluation
     - xpath.h, xpath.c: add a mechanism of frame for XPath evaluation when
       entering a function or a scoped evaluation
     - f5048b3e71fc30ad096970b8df6e7af073bae4cb
     - CVE-2011-2821
   * SECURITY UPDATE: fix double free in XPath evaluation
     - xpath.c: fix missing error status in XPath evaluation
     - 1d4526f6f4ec8d18c40e2a09b387652a6c1aa2cd
     - CVE-2011-2834
   * SECURITY UPDATE: fix out of bounds read
     - parser.c: make sure the parser returns when getting a Stop order
     - 77404b8b69bc122d12231807abf1a837d121b551
     - CVE-2011-3905
   * SECURITY UPDATE: fix heap overflow
     - parser.c: fix an allocation error when copying entities
     - 5bd3c061823a8499b27422aee04ea20aae24f03e
     - CVE-2011-3919
Checksums-Sha1: 
 414f085f00ca45c623e09686c70ec52870190d10 2287 libxml2_2.7.7.dfsg-4ubuntu0.3.dsc
 99e99c506055adf54ae4af8c64a3345b3515978c 105658 libxml2_2.7.7.dfsg-4ubuntu0.3.diff.gz
Checksums-Sha256: 
 65168fb996412667f0976c639aab483e35251dd144d43cf5fab6545de397fda1 2287 libxml2_2.7.7.dfsg-4ubuntu0.3.dsc
 60bfd578bfa9b6877f119cb8d294dcb6fabea2e3543378f7d114328ec8dc8ac5 105658 libxml2_2.7.7.dfsg-4ubuntu0.3.diff.gz
Files: 
 6dd9f703fb2674087af7e4374ecc1c53 2287 libs optional libxml2_2.7.7.dfsg-4ubuntu0.3.dsc
 f1a7329bb9474638837fda11836fe350 105658 libs optional libxml2_2.7.7.dfsg-4ubuntu0.3.diff.gz
Original-Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs at lists.alioth.debian.org>


More information about the Maverick-changes mailing list