Bug#685584: xml-light: CVE-2012-3514

2013-01-17 Thread Jonathan Wiltshire
Package: xml-light Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.7)

Bug#685584: xml-light: CVE-2012-3514

2012-08-21 Thread Moritz Muehlenhoff
Package: xml-light Severity: grave Tags: security Justification: user security hole This was posted to oss-security: -- Xml-Light has been moved to google code SVN here : http://ocamllibs.googlecode.com/svn/trunk/xml-light/ I've applied a fix in r234 by using String Map instead of Hashtbl for DT