[ubuntu/xenial-proposed] libxml2 2.9.2+zdfsg1-4ubuntu1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Fri Nov 13 13:49:14 UTC 2015


libxml2 (2.9.2+zdfsg1-4ubuntu1) xenial; urgency=medium

  * SECURITY UPDATE: overflow in conditional sections
    - debian/patches/CVE-2015-7942.patch: properly check input in parser.c.
    - CVE-2015-7942
  * SECURITY UPDATE: denial of service via crafted document with xz
    - debian/patches/CVE-2015-8035.patch: check for error in xzlib.c.
    - CVE-2015-8035
  * debian/patches/re-enable-xz-support.patch: re-enable xz support that
    was disabled by mistake in 2.9.2.
  * debian/libxml2.symbols: added new symbol.

Date: Fri, 13 Nov 2015 07:30:36 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/libxml2/2.9.2+zdfsg1-4ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 13 Nov 2015 07:30:36 -0500
Source: libxml2
Binary: libxml2 libxml2-utils libxml2-utils-dbg libxml2-dev libxml2-dbg libxml2-doc python-libxml2 python-libxml2-dbg libxml2-udeb
Architecture: source
Version: 2.9.2+zdfsg1-4ubuntu1
Distribution: xenial
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 libxml2    - GNOME XML library
 libxml2-dbg - Debugging symbols for the GNOME XML library
 libxml2-dev - Development files for the GNOME XML library
 libxml2-doc - Documentation for the GNOME XML library
 libxml2-udeb - GNOME XML library - minimal runtime (udeb)
 libxml2-utils - XML utilities
 libxml2-utils-dbg - XML utilities (debug extension)
 python-libxml2 - Python bindings for the GNOME XML library
 python-libxml2-dbg - Python bindings for the GNOME XML library (debug extension)
Changes:
 libxml2 (2.9.2+zdfsg1-4ubuntu1) xenial; urgency=medium
 .
   * SECURITY UPDATE: overflow in conditional sections
     - debian/patches/CVE-2015-7942.patch: properly check input in parser.c.
     - CVE-2015-7942
   * SECURITY UPDATE: denial of service via crafted document with xz
     - debian/patches/CVE-2015-8035.patch: check for error in xzlib.c.
     - CVE-2015-8035
   * debian/patches/re-enable-xz-support.patch: re-enable xz support that
     was disabled by mistake in 2.9.2.
   * debian/libxml2.symbols: added new symbol.
Checksums-Sha1:
 2a1b3532c23c98c911418cd6362dbba456bc6780 2757 libxml2_2.9.2+zdfsg1-4ubuntu1.dsc
 061c45f9e6729df86f93431a6bcb9897ec00a10e 30660 libxml2_2.9.2+zdfsg1-4ubuntu1.debian.tar.xz
Checksums-Sha256:
 e6331a24af06f5f597379c00b9c71bdf7e38dde4ca14d22e171d2ae3402a63cc 2757 libxml2_2.9.2+zdfsg1-4ubuntu1.dsc
 ad2585ed4349a8097e0ff0246517d12289ce045efe4472e0de6082772c5a49b0 30660 libxml2_2.9.2+zdfsg1-4ubuntu1.debian.tar.xz
Files:
 8d5cb817512cb51d17bc46d5b342b9af 2757 libs optional libxml2_2.9.2+zdfsg1-4ubuntu1.dsc
 14d283a095ad49a2025a52dbd3c0b66e 30660 libs optional libxml2_2.9.2+zdfsg1-4ubuntu1.debian.tar.xz
Original-Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJWReGjAAoJEGVp2FWnRL6TZGQP/0Mje2iZ5DjBfLyt6M0Cqm/Q
mMtwTgk72alBjpkC7g1fWidPQ+NMA1gQb9pgVMR3LyPxRvIZ6RRXNlmpUu/hKw8+
5DqWJ4sQrBEtK+OAqMgA3t788glz3A17ErK2TihK6MfJ8ZBlEiksu831xTFkykCX
rPNQpJ+A3QSRTk24YYKvWj79hapPlywNannvyNWBpm0RDRZdjsDleq11VEBlQZVG
x+ucmGbsYSi9hs8mFbmFD7zWHNOdYyprZLVRLo1pBjKF6Tnt3O9PzONzHOXKpI5v
rMrqYu1/5oaMq4lOgVY0kYzVPIzphSKJj/NyJvBhnl38rpczjLs67cHGIxo3EHvL
s4igIUJlyLkCDLS/awEO65+oCLbvNhGP1J2XUW8U3q7xxie1MTl9eBFXNE/6ub7p
gR5AjQoK5a7gfS07Tk5lPUBxMKYxK4az79rqEjQpAh0QDdkXPtOUEeRFTfjPxHMJ
jLMB6JV6yOTFeSnab0fsVb2RqrGSTxArUqNPVC9Qo24gN+s3kbF7oOLhL5HLrKG/
9rfKi7cvvi93HFPPSdpFxM/uy2+o8EzVluXjqcnHa/kXRcwNG3aXKVsJwdYzFtt0
gQjACgfefIaZ5QwMWdiHAfTw3qopv4oXPPQwKe6Y3Ona9Og6htldrexPx8cINceD
go0KsjiX6C9ab55ON/dd
=Znct
-----END PGP SIGNATURE-----


More information about the Xenial-changes mailing list