[ubuntu/precise-updates] librsvg 2.36.1-0ubuntu1.1 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Mon Mar 17 11:58:08 UTC 2014


librsvg (2.36.1-0ubuntu1.1) precise-security; urgency=medium

  * SECURITY UPDATE: arbitrary file disclosure via XML External Entity
    (XXE) issue.
    - debian/patches/CVE-2013-1881.patch: implement stricter policy in
      rsvg-base.c, rsvg-css.c, rsvg-io.c, rsvg-private.h.
    - debian/control*: added appropriate Breaks as this updates requires
      a fix to also be added to gtk+3.0.
    - CVE-2013-1881

Date: 2014-03-14 15:21:15.409767+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/precise/+source/librsvg/2.36.1-0ubuntu1.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Precise-changes mailing list