[ubuntu/oneiric-security] libxml2 2.7.8.dfsg-4ubuntu0.1 (Accepted)

Jamie Strandboge jamie at ubuntu.com
Thu Jan 19 17:33:25 UTC 2012


libxml2 (2.7.8.dfsg-4ubuntu0.1) oneiric-security; urgency=low

  * SECURITY UPDATE: fix off-by-one leading to denial of service
    - encoding.c: adjust calculation of space available
    - 69f04562f75212bfcabecd190ea8b06ace28ece2
    - CVE-2011-0216
  * SECURITY UPDATE: fix double free in XPath evaluation
    - xpath.h, xpath.c: add a mechanism of frame for XPath evaluation when
      entering a function or a scoped evaluation
    - f5048b3e71fc30ad096970b8df6e7af073bae4cb
    - CVE-2011-2821
  * SECURITY UPDATE: fix double free in XPath evaluation
    - xpath.c: fix missing error status in XPath evaluation
    - 1d4526f6f4ec8d18c40e2a09b387652a6c1aa2cd
    - CVE-2011-2834
  * SECURITY UPDATE: fix out of bounds read
    - parser.c: make sure the parser returns when getting a Stop order
    - 77404b8b69bc122d12231807abf1a837d121b551
    - CVE-2011-3905
  * SECURITY UPDATE: fix heap overflow
    - parser.c: fix an allocation error when copying entities
    - 5bd3c061823a8499b27422aee04ea20aae24f03e
    - CVE-2011-3919

Date: Wed, 18 Jan 2012 13:12:25 -0600
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/oneiric/+source/libxml2/2.7.8.dfsg-4ubuntu0.1
-------------- next part --------------
Format: 1.8
Date: Wed, 18 Jan 2012 13:12:25 -0600
Source: libxml2
Binary: libxml2 libxml2-utils libxml2-dev libxml2-dbg libxml2-doc python-libxml2 python-libxml2-dbg libxml2-udeb
Architecture: source
Version: 2.7.8.dfsg-4ubuntu0.1
Distribution: oneiric-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description: 
 libxml2    - GNOME XML library
 libxml2-dbg - Debugging symbols for the GNOME XML library
 libxml2-dev - Development files for the GNOME XML library
 libxml2-doc - Documentation for the GNOME XML library
 libxml2-udeb - GNOME XML library - minimal runtime (udeb)
 libxml2-utils - XML utilities
 python-libxml2 - Python bindings for the GNOME XML library
 python-libxml2-dbg - Python bindings for the GNOME XML library (debug extension)
Changes: 
 libxml2 (2.7.8.dfsg-4ubuntu0.1) oneiric-security; urgency=low
 .
   * SECURITY UPDATE: fix off-by-one leading to denial of service
     - encoding.c: adjust calculation of space available
     - 69f04562f75212bfcabecd190ea8b06ace28ece2
     - CVE-2011-0216
   * SECURITY UPDATE: fix double free in XPath evaluation
     - xpath.h, xpath.c: add a mechanism of frame for XPath evaluation when
       entering a function or a scoped evaluation
     - f5048b3e71fc30ad096970b8df6e7af073bae4cb
     - CVE-2011-2821
   * SECURITY UPDATE: fix double free in XPath evaluation
     - xpath.c: fix missing error status in XPath evaluation
     - 1d4526f6f4ec8d18c40e2a09b387652a6c1aa2cd
     - CVE-2011-2834
   * SECURITY UPDATE: fix out of bounds read
     - parser.c: make sure the parser returns when getting a Stop order
     - 77404b8b69bc122d12231807abf1a837d121b551
     - CVE-2011-3905
   * SECURITY UPDATE: fix heap overflow
     - parser.c: fix an allocation error when copying entities
     - 5bd3c061823a8499b27422aee04ea20aae24f03e
     - CVE-2011-3919
Checksums-Sha1: 
 907e2c8a71ed6f45eb543d0d88b0b02d4c4a1a29 2262 libxml2_2.7.8.dfsg-4ubuntu0.1.dsc
 9ec5b5993cfb85088bc0a7360260f30a668c045a 121051 libxml2_2.7.8.dfsg-4ubuntu0.1.diff.gz
Checksums-Sha256: 
 72c1f3d8aaa7006d587348cecc62a8dfafdc49a0ba0edc32f5b0d20842155b83 2262 libxml2_2.7.8.dfsg-4ubuntu0.1.dsc
 1ff8ed632709088c7dd75e027672e94e18e34232bb10250a19333a077ad113cb 121051 libxml2_2.7.8.dfsg-4ubuntu0.1.diff.gz
Files: 
 1f5956f3845e580cd413eac904a0a646 2262 libs optional libxml2_2.7.8.dfsg-4ubuntu0.1.dsc
 3ef4bd966eb106e80b70ade2807cf404 121051 libs optional libxml2_2.7.8.dfsg-4ubuntu0.1.diff.gz
Original-Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs at lists.alioth.debian.org>


More information about the Oneiric-changes mailing list