Bug#705722: [xml/sgml-pkgs] Bug#705722: libxml2: CVE-2013-1969

2013-04-19 Thread Salvatore Bonaccorso
Hi Aron On Fri, Apr 19, 2013 at 05:29:59PM +0800, Aron Xu wrote: > found 705722 2.9.0+dfsg1-4 > thanks > > I think this bug only exist from 2.9.0? xmlBufGetInputBase() does not > exist before that. Thanks a lot for your quick checking and marking version accordingly. (I did not check the versio

Processed: Re: [xml/sgml-pkgs] Bug#705722: libxml2: CVE-2013-1969

2013-04-19 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 705722 2.9.0+dfsg1-4 Bug #705722 [libxml2] libxml2: CVE-2013-1969 Marked as found in versions libxml2/2.9.0+dfsg1-4. > thanks Stopping processing here. Please contact me if you need assistance. -- 705722: http://bugs.debian.org/cgi-bin/bug

Bug#705722: [xml/sgml-pkgs] Bug#705722: libxml2: CVE-2013-1969

2013-04-19 Thread Aron Xu
found 705722 2.9.0+dfsg1-4 thanks I think this bug only exist from 2.9.0? xmlBufGetInputBase() does not exist before that. On Fri, Apr 19, 2013 at 12:51 PM, Salvatore Bonaccorso wrote: > Package: libxml2 > Severity: grave > Tags: security patch upstream > > Hi, > > the following vulnerability wa

Bug#705722: libxml2: CVE-2013-1969

2013-04-19 Thread John Paul Adrian Glaubitz
Attaching the patch for convenience. I'd be happy to step up and NMU this for Wheezy to get it fixed as soon as possible. I will be preparing the NMU anyway and attach the debdiff here for review. Adrian -- .''`. John Paul Adrian Glaubitz : :' : Debian Developer - glaub...@debian.org `. `

Bug#705722: libxml2: CVE-2013-1969

2013-04-18 Thread Salvatore Bonaccorso
Package: libxml2 Severity: grave Tags: security patch upstream Hi, the following vulnerability was published for libxml2. CVE-2013-1969[0]: se-after-free error in "htmlParseChunk()" and "xmldecl_done()" If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilitie