hi,

just a quick ack:

i've imported the patches into git but one of them does not apply:

Applying patch CVE-2009-3560.patch
patching file lib/expat/xmlparse/xmlparse.c
Hunk #1 FAILED at 2330.
1 out of 1 hunk FAILED -- rejects in file lib/expat/xmlparse/xmlparse.c
Patch CVE-2009-3560.patch does not apply (enforce with -f)

i've taken a very cursory look but can't tell if this has already been
addressed for the unstable version; there are a number of switch statements
in this file and i'm not sure which one is supposed to be patched ("-p" output
from diff might help there).  in one of the switch statements at least there's
a default case that seems to do the same error handling, though i'm not
sure if it's sufficient to address the issue.  is there some test case
i can use to verify the error?

i'll look closer when i have a chance but if you have any further info that
could help it would be appreciated.

thanks,
        sean

Attachment: signature.asc
Description: Digital signature

Reply via email to