-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 29 Nov 2015 19:00:37 +0100 Source: libxml2 Binary: libxml2 libxml2-utils libxml2-dev libxml2-dbg libxml2-doc python-libxml2 python-libxml2-dbg Architecture: source i386 all Version: 2.7.8.dfsg-2+squeeze15 Distribution: squeeze-lts Urgency: high Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: libxml2 - GNOME XML library libxml2-dbg - Debugging symbols for the GNOME XML library libxml2-dev - Development files for the GNOME XML library libxml2-doc - Documentation for the GNOME XML library libxml2-utils - XML utilities python-libxml2 - Python bindings for the GNOME XML library python-libxml2-dbg - Python bindings for the GNOME XML library (debug extension) Closes: 806384 Changes: libxml2 (2.7.8.dfsg-2+squeeze15) squeeze-lts; urgency=high . * Non-maintainer upload by the Squeeze LTS Team. * fix off by one error for previous patch for CVE-2015-7942 (thanks to Salvatore for spotting this) * Add patch for CVE-2015-8241 (Closes: #806384) Buffer overread with XML parser in xmlNextChar * Add patch for CVE-2015-8317_751631 issues in the xmlParseXMLDecl function: If we fail conversing the current input stream while processing the encoding declaration of the XMLDecl then it's safer to just abort there and not try to report further errors. * Add patch for CVE-2015-8317_51603 If the string is not properly terminated do not try to convert to the given encoding. Checksums-Sha1: dd3188ca7d1346b841cd80e34ff4d253e4fef7ca 2311 libxml2_2.7.8.dfsg-2+squeeze15.dsc bf481743478da6899a65507a34b67731466960dd 3509930 libxml2_2.7.8.dfsg.orig.tar.gz 4cd97e8bbea7acf251cd6c1e903b206ccde4a18c 131443 libxml2_2.7.8.dfsg-2+squeeze15.diff.gz a002dfafc4347f4acd1e5463d73cc3926c6c1239 830820 libxml2_2.7.8.dfsg-2+squeeze15_i386.deb ebb840c6279b3ae006721e995674a6b01956ebf0 91716 libxml2-utils_2.7.8.dfsg-2+squeeze15_i386.deb 6d4ed33787fabff6028c1c8268a228dcbb0f7b95 753912 libxml2-dev_2.7.8.dfsg-2+squeeze15_i386.deb 322e4f8ca92e3655cb25fa5e2b625bd9875f108e 992502 libxml2-dbg_2.7.8.dfsg-2+squeeze15_i386.deb f16cbad08d0495c133d421933fa1b64e5ab724e6 1383224 libxml2-doc_2.7.8.dfsg-2+squeeze15_all.deb fcecb4ea46791259f56f66500d0bab5a18ae0d3f 310302 python-libxml2_2.7.8.dfsg-2+squeeze15_i386.deb 16c14b8275d1d679be570774c15d74dc60c78a99 825730 python-libxml2-dbg_2.7.8.dfsg-2+squeeze15_i386.deb Checksums-Sha256: 161ee35397cd354a163f255ba60a6aa2816439598bc73872549aa49d5d7da35d 2311 libxml2_2.7.8.dfsg-2+squeeze15.dsc 9f5262963fda356708903b42ff862a816c714582d0cf41477a8b3839945f0e43 3509930 libxml2_2.7.8.dfsg.orig.tar.gz 5e9688b86d50fc1952a0cce89446433e7faf7b6addf65597a874d7b41b7d655b 131443 libxml2_2.7.8.dfsg-2+squeeze15.diff.gz 952acc1e76f079c13a25def25253d5b8caf17415959f28ed8fcf570ae3e7ce17 830820 libxml2_2.7.8.dfsg-2+squeeze15_i386.deb ea329ff5bc638d5e11aa3f87fe9c825bc3b00009381736bbcd3e0709613f0b1b 91716 libxml2-utils_2.7.8.dfsg-2+squeeze15_i386.deb 159e6c572510b701d0bbabb62ef89481e40a086c51c7b42197b423a9daadc1ed 753912 libxml2-dev_2.7.8.dfsg-2+squeeze15_i386.deb 999882ac8acc5db6555c2517d0136a91eeb590abfe70bacad07bcf1afe1daa89 992502 libxml2-dbg_2.7.8.dfsg-2+squeeze15_i386.deb c694624b7727a82cccbf9fc36c1b6d46ed85b8236b37f9205e92a817d22fc3f2 1383224 libxml2-doc_2.7.8.dfsg-2+squeeze15_all.deb 8ae2e6535e88d6810ee704a04939e0cbafc30eb8868aa36513936e9bc511ed32 310302 python-libxml2_2.7.8.dfsg-2+squeeze15_i386.deb e99a118c85c8d1c91572f617e7569a0915b595fd58f2320c783f943a20b85ecb 825730 python-libxml2-dbg_2.7.8.dfsg-2+squeeze15_i386.deb Files: 03aa2aab087d855318980bef527b9ba4 2311 libs optional libxml2_2.7.8.dfsg-2+squeeze15.dsc 116fd86aa1b392dfe38d6b17613deebb 3509930 libs optional libxml2_2.7.8.dfsg.orig.tar.gz 42bac79261394c74efc869d1580516cb 131443 libs optional libxml2_2.7.8.dfsg-2+squeeze15.diff.gz 7e248b454e3d0525a55e04cb05276849 830820 libs standard libxml2_2.7.8.dfsg-2+squeeze15_i386.deb 66d6173811e837458bb503fd51f5948b 91716 text optional libxml2-utils_2.7.8.dfsg-2+squeeze15_i386.deb e74a479d6f65efc66450f6e1590f2650 753912 libdevel optional libxml2-dev_2.7.8.dfsg-2+squeeze15_i386.deb 6c88199fe30c196d5e47bbd2670beda6 992502 debug extra libxml2-dbg_2.7.8.dfsg-2+squeeze15_i386.deb bdd99690f71f71a53973f388328f78a2 1383224 doc optional libxml2-doc_2.7.8.dfsg-2+squeeze15_all.deb c3123697a9a2301edb2b2457e91f9621 310302 python optional python-libxml2_2.7.8.dfsg-2+squeeze15_i386.deb 42b2bc3fb2ad226e474b7ec22cdce697 825730 debug extra python-libxml2-dbg_2.7.8.dfsg-2+squeeze15_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJWW3K7XxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ2MjAxRkJGRkRCQkRFMDc4MjJFQUJCOTY5 NkZDQUMwRDM4N0I1ODQ3AAoJEJb8rA04e1hHgcsP/3ZiN7KhfjvFDzMSX6HC8y7U mpSgiUYx+mNYqqc9Unq7cS0/DSuCUL1gK2t6s/RrKqD9jVpnAdKWwwknuCtMbLWl oqNfKnIMeI325eHIGeox5TX4my5yfqjaHOVjboGoF65mTTPXoXZ8B6I5dDugJQsl F2wh/mt1V8H4Gk0qXy078vGo8W/xacVx+FsT3VVTCZdGUtSLqVs6/BJIaY4j3/PK tmdua5+sSydEIvoniGuzX6D0TG7OPvOaugnY8oKaEP12TXdMeKKAE44li6QvK8mP I54x6ZvpkeR90lBjp5G4rLyro2sPsypQA3JGqSBgIGi1rYFbiyGDTyjwC3EzvrjL MS8S0HjHoT6nu2vNdRipm5BoiGRcwICXySK/+lSB7tUtuq1uRik878X9Uyk02rMg MgMFhdv+fihP//NuYZQ2P2/1ruRoFjrh4jid++h1Vmb0tlbCaODLKdp+qNd6ClR9 wEpKs51q+oZkk5KGMyGmdWTO2m7dRbM86PebYmtF14dUQ2uXyxn4b15Rf4Zmtgkp vm139YQ0/srGgoMX5qNpoOHGFc2Yo2gyxsg3a6kY1wF7XXrE2TmLLns8nVLnYRxZ R/mz8VyaYGbAvTa2Teznt0UuwmjkaW0hpb8FWNxQvKJ8CM0IB1fuD6t3xcosF4UK 56GecU9WukUpGn3L9yhQ =gKva -----END PGP SIGNATURE-----