-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 15 Apr 2023 16:25:06 +0200 Source: libxml2 Architecture: source Version: 2.9.14+dfsg-1.2 Distribution: unstable Urgency: medium Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 1034436 1034437 Changes: libxml2 (2.9.14+dfsg-1.2) unstable; urgency=medium . * Non-maintainer upload. * schemas: Fix null-pointer-deref in xmlSchemaCheckCOSSTDerivedOK * Fix null deref in xmlSchemaFixupComplexType (CVE-2023-28484) (Closes: #1034436) * Hashing of empty dict strings isn't deterministic (CVE-2023-29469) (Closes: #1034437) Checksums-Sha1: 60fa8479ea8ab9060db46acc0cf5d7deef8c2aa4 3078 libxml2_2.9.14+dfsg-1.2.dsc d6d604095c6e3c908ed04981ebda7dc9c111d5bf 34708 libxml2_2.9.14+dfsg-1.2.debian.tar.xz Checksums-Sha256: 16b9eb6eaa09a0499340847490ee29bbea2ffdc182107d9d1ee7b7714a6b1750 3078 libxml2_2.9.14+dfsg-1.2.dsc 9e40f185aa28abe94d16a8c10b9b934b063c5b2a13ac77eb10518ac26c6c594d 34708 libxml2_2.9.14+dfsg-1.2.debian.tar.xz Files: fce29a5c9c03a071f660e90c049ef874 3078 libs optional libxml2_2.9.14+dfsg-1.2.dsc c8b8fac6d3f2b8473d2e3cb4d30c33cd 34708 libs optional libxml2_2.9.14+dfsg-1.2.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmQ6uwpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89E98EP/j3gnroDadw+feLBnAUma75+7FMTL2ri 2zHc3keB/TmHPiIgUvx59k8x3BH7dRpzPQW9HYk9WSGTcVSi3R6rvU0jb68OklE3 xCGtE5sEvtb91/mbSbPoN6ZuXTi2hnYWwKu3dF/YyuWfmgJQ6eHGGtKCqLazBzj/ wU5vu0QawBAUALcZ0VwPSeibn0+uvjpPKzYuUZjXbT2UK7GhWHhyPYkl/kAsli5o nBS1278wt/3TwzJMkc+J9AIsU/IWzi1y8jDE/g75pIjsOJeVItn7PqfLuxlhKYyj Sc4Sn8Ikz07s0D8cbj+43TMPnfF0SMrzMFyDZbFk5mEXWG+0yACnphVfripfJsCt BJS/21k4RqHo+3g0rhk7B3QbP5yDQG/2JAkVpZWOI20Jw5VmeF576iSTWdBAFimj 8Z9neVjkK1oFtxPEwvZIPH5xAPpFT2sQmQV0BTHTj6yEt+M7lj8aBE85haQsV9MZ jy6EW4Oy6JtxFg5+iE4pMBaICBu30PWFqFITiiK34f3W0ENOe0WzUIIuFzNCaYYj I/vT66jAFEnf+nmBeX4borxrhNgGNNNBamngjzgftPIseqM/DBnluGWqX6ZYmZZu FdBUjFeLwgjY75yAcI3e6EJ3NRDJNslfApZ43P5tSuxmBfmwFV9SaA7XD3uYXAN/ CVZ/XyuGhCnD =qb6t -----END PGP SIGNATURE-----