-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 17 Dec 2016 19:42:58 +0100 Source: libxml2 Binary: libxml2 libxml2-utils libxml2-utils-dbg libxml2-dev libxml2-dbg libxml2-doc python-libxml2 python-libxml2-dbg Architecture: all source Version: 2.9.1+dfsg1-5+deb8u4 Distribution: jessie-security Urgency: high Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 840553 840554 Description: libxml2 - GNOME XML library libxml2-dbg - Debugging symbols for the GNOME XML library libxml2-dev - Development files for the GNOME XML library libxml2-doc - Documentation for the GNOME XML library libxml2-utils - XML utilities libxml2-utils-dbg - XML utilities (debug extension) python-libxml2 - Python bindings for the GNOME XML library python-libxml2-dbg - Python bindings for the GNOME XML library (debug extension) Changes: libxml2 (2.9.1+dfsg1-5+deb8u4) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix comparison with root node in xmlXPathCmpNodes * Fix XPointer paths beginning with range-to (CVE-2016-5131) (Closes: #840554) * Disallow namespace nodes in XPointer ranges (CVE-2016-4658) (Closes: #840553) * Fix more NULL pointer derefs in xpointer.c Checksums-Sha1: efa2de3e0b0661c49d703e910cbb6da3641e1e17 2760 libxml2_2.9.1+dfsg1-5+deb8u4.dsc e27c423442c4d8fc2aae872da630510e93fda912 66756 libxml2_2.9.1+dfsg1-5+deb8u4.debian.tar.xz 04dff14d8a76e6eee670540c854b8af236130901 814770 libxml2-doc_2.9.1+dfsg1-5+deb8u4_all.deb Checksums-Sha256: 23f9a9935227718fd2921abb484c129617325e1306d8525b3dcec1611df01096 2760 libxml2_2.9.1+dfsg1-5+deb8u4.dsc cda8374910db4e2a06b2515123dbe0b714f7f647532dc305f03c2a094175e706 66756 libxml2_2.9.1+dfsg1-5+deb8u4.debian.tar.xz 077cae3381c2ebfe6537190bf9204d953c3c96ce181474f4027cc8ead9ba8fc4 814770 libxml2-doc_2.9.1+dfsg1-5+deb8u4_all.deb Files: f98c7d9f59e95b354ac6c443f0df4425 2760 libs optional libxml2_2.9.1+dfsg1-5+deb8u4.dsc baae4e43fa95061a79014dd525078545 66756 libs optional libxml2_2.9.1+dfsg1-5+deb8u4.debian.tar.xz 3cb06339d607acd3d8a1e763ea3065d9 814770 doc optional libxml2-doc_2.9.1+dfsg1-5+deb8u4_all.deb -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlhViIdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89E7pMQAJVMqx00hx6RhbQcovt/n1WQqXWPyVNC htgz3lSelGZFkDe8nyeHDzw6Br5Q/u+kJetD3A7IaHGMXNsTVDh9r6mGAmJhsd4O xx9snz2KcUmRwqMS53s78FRSlUjrO32klCD5x1kwPjcYwDSHMWerUU53I7n1enHj K/g96ARB1cVxelqy2to785iRt6NFfbRRUz3c2J/SMSMAVZv0/6zEhsE+r6ccNTWC X28mhmEC5wpD+MuLb/USyMp7uPt6SbvwSLX0dzQUaj/2yZ2b4eOxTgrQvmoxe1+8 3LQqep8FxlD0MBUp3pKbNsuMi6a6h7NV+jhbe0dovngNP+BjnTK+i+DZgwnO/9w3 vPvsRREBBvwrISZrTugB4zJazgaMfEI7+mo6EI49esV3qaPl+WZXz9azJZy6vI+0 3jQk6qNe40dtaWQCY3ZB/iaZpJF3K0xioBHVJwVF7sAiwGFq89l4nMp/8gGsL73i 2QcC9fSNj9MIjGTtfAle45jnY9oJU/oSKxzrKmNYY5pjzhNOs/8lGxgAi7bkSHBO JlQ7wldIYRt6wqXQpnKdxalh9q+E3AYTDRO+uOOZHpIUUOR+qa8TP1EzYozfuDka XWfJJioG4nnSkd9ySMZLIs+miorMih8SuZ3/q4XGpgcwCVDrx3YVeV0b/4TAj/2E 42EWYcTMuOzf =u5sF -----END PGP SIGNATURE-----