Publishing details
Changelog
expat (2.0.1-7.2ubuntu1.4) precise-security; urgency=medium
* SECURITY UPDATE: unanticipated internal calls to srand
- debian/patches/CVE-2012-6702-1.dpatch: remove srand, use more entropy
in lib/xmlparse.c.
- debian/patches/CVE-2012-6702-2.dpatch: use a prime that fits 32bits
on 32bit platforms in lib/xmlparse.c.
- CVE-2012-6702
* SECURITY UPDATE: use of too little entropy
- debian/patches/CVE-2016-5300-1.dpatch: extract method
gather_time_entropy in lib/xmlparse.c.
- debian/patches/CVE-2016-5300-2.dpatch: extract entropy from
XML_Parser address in lib/xmlparse.c.
- CVE-2016-5300
-- Marc Deslauriers <email address hidden> Fri, 10 Jun 2016 08:54:12 -0400
Builds
Package files