libxml2 2.9.2+dfsg1-3ubuntu0.2 source package in Ubuntu

Changelog

libxml2 (2.9.2+dfsg1-3ubuntu0.2) vivid-security; urgency=medium

  * SECURITY UPDATE: denial of service via entity expansion issue
    - debian/patches/CVE-2015-5312.patch: properly exit when entity
      expansion is detected in parser.c.
    - CVE-2015-5312
  * SECURITY UPDATE: heap buffer overflow in xmlDictComputeFastQKey
    - debian/patches/CVE-2015-7497.patch: check offset in dict.c.
    - CVE-2015-7497
  * SECURITY UPDATE: denial of service via encoding conversion failures
    - debian/patches/CVE-2015-7498.patch: avoid processing entities after
      encoding conversion failures in parser.c.
    - CVE-2015-7498
  * SECURITY UPDATE: out of bounds read in xmlGROW
    - debian/patches/CVE-2015-7499-1.patch: add xmlHaltParser() to stop the
      parser in parser.c.
    - debian/patches/CVE-2015-7499-2.patch: check input in parser.c.
    - CVE-2015-7499
  * SECURITY UPDATE: out of bounds read in xmlParseMisc
    - debian/patches/CVE-2015-7500.patch: check entity boundaries in
      parser.c.
    - CVE-2015-7500
  * SECURITY UPDATE: denial of service via extra processing of MarkupDecl
    - debian/patches/CVE-2015-8241.patch: add extra EOF check in parser.c.
    - CVE-2015-8241
  * SECURITY UPDATE: buffer overead with HTML parser in push mode
    - debian/patches/CVE-2015-8242.patch: use pointer in the input in
      HTMLparser.c.
    - CVE-2015-8242
  * SECURITY UPDATE: denial of service via encoding failures
    - debian/patches/CVE-2015-8317-1.patch: do not process encoding values
      if the declaration is broken in parser.c.
    - debian/patches/CVE-2015-8317-2.patch: fail parsing if the encoding
      conversion failed in parser.c.
    - CVE-2015-8317

 -- Marc Deslauriers <email address hidden>  Wed, 09 Dec 2015 11:35:28 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Vivid
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
libxml2_2.9.2+dfsg1.orig.tar.xz 2.4 MiB 0e2ba8bcdb181343f78acfacd342f211f70894b904747367c52011ab9a096776
libxml2_2.9.2+dfsg1-3ubuntu0.2.debian.tar.xz 29.9 KiB a85613b9034d74dc39a9db2d644ca0e895f94989230972f84f3725c4071ed23e
libxml2_2.9.2+dfsg1-3ubuntu0.2.dsc 2.7 KiB 8b33a5421abcb6753361250de88ea9c77740f38862177932d3b8d4d0bf3d3d8b

View changes file

Binary packages built by this source

libxml2: No summary available for libxml2 in ubuntu vivid.

No description available for libxml2 in ubuntu vivid.

libxml2-dbg: No summary available for libxml2-dbg in ubuntu vivid.

No description available for libxml2-dbg in ubuntu vivid.

libxml2-dbgsym: No summary available for libxml2-dbgsym in ubuntu vivid.

No description available for libxml2-dbgsym in ubuntu vivid.

libxml2-dev: No summary available for libxml2-dev in ubuntu vivid.

No description available for libxml2-dev in ubuntu vivid.

libxml2-dev-dbgsym: No summary available for libxml2-dev-dbgsym in ubuntu vivid.

No description available for libxml2-dev-dbgsym in ubuntu vivid.

libxml2-doc: No summary available for libxml2-doc in ubuntu vivid.

No description available for libxml2-doc in ubuntu vivid.

libxml2-udeb: No summary available for libxml2-udeb in ubuntu vivid.

No description available for libxml2-udeb in ubuntu vivid.

libxml2-udeb-dbgsym: No summary available for libxml2-udeb-dbgsym in ubuntu vivid.

No description available for libxml2-udeb-dbgsym in ubuntu vivid.

libxml2-utils: No summary available for libxml2-utils in ubuntu vivid.

No description available for libxml2-utils in ubuntu vivid.

libxml2-utils-dbg: No summary available for libxml2-utils-dbg in ubuntu vivid.

No description available for libxml2-utils-dbg in ubuntu vivid.

libxml2-utils-dbgsym: No summary available for libxml2-utils-dbgsym in ubuntu vivid.

No description available for libxml2-utils-dbgsym in ubuntu vivid.

python-libxml2: No summary available for python-libxml2 in ubuntu vivid.

No description available for python-libxml2 in ubuntu vivid.

python-libxml2-dbg: No summary available for python-libxml2-dbg in ubuntu vivid.

No description available for python-libxml2-dbg in ubuntu vivid.

python-libxml2-dbgsym: No summary available for python-libxml2-dbgsym in ubuntu vivid.

No description available for python-libxml2-dbgsym in ubuntu vivid.