Format: 1.8 Date: Fri, 21 Apr 2023 17:23:48 +0200 Source: libxml2 Architecture: source Version: 2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1 Distribution: jammy Urgency: medium Maintainer: Debian XML/SGML Group Changed-By: Ondřej Surý Closes: 1022224 1022225 1034436 1034437 Changes: libxml2 (2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1) jammy; urgency=medium . * No-change backport to jammy . libxml2 (2.9.14+dfsg-0.1) unstable; urgency=medium . * Fix multiple security issues: + schemas: Fix null-pointer-deref in xmlSchemaCheckCOSSTDerivedOK + Fix null deref in xmlSchemaFixupComplexType (CVE-2023-28484) (Closes: #1034436) + Hashing of empty dict strings isn't deterministic (CVE-2023-29469) (Closes: #1034437) + Fix integer overflows with XML_PARSE_HUGE (CVE-2022-40303) (Closes: #1022224) + Fix dict corruption caused by entity reference cycles (CVE-2022-40304) (Closes: #1022225) . libxml2 (2.9.14+dfsg-0) unstable; urgency=medium . * New upstream version 2.9.14+dfsg Checksums-Sha1: c84aecaab44018f27919d921d68061da14c9b384 2967 libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1.dsc b41615e638174b4e36845c68d4b305dd6a6b541f 2351200 libxml2_2.9.14+dfsg.orig.tar.xz 937b17d720a6139023a1c12708dba759e30e08b9 34248 libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1.debian.tar.xz 1985c8aa3975a676930d9c20f2b430bcaaaf7990 10793 libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1_source.buildinfo Checksums-Sha256: c19afa1203fc19d543c9525c018d82fb5fa099de151a9bce24f90580bc676409 2967 libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1.dsc 4fe913dec8b1ab89d13b489b419a8203176ea39e931eaa0d25b17eafb9c279e9 2351200 libxml2_2.9.14+dfsg.orig.tar.xz a05bf14d02b6976811498cf50fbee7dc65c6711c4dd76506001061beb18ed50e 34248 libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1.debian.tar.xz eadb3ee96e46f9380e07ddfca0b95d28ef4f4cb004bbc018f9422c3cdc8dc342 10793 libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1_source.buildinfo Files: 737bd705c07efd2021e4dfb2c2f978a5 2967 libs optional libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1.dsc bbcae2f48d1c9b1413ef953ce87e9346 2351200 libs optional libxml2_2.9.14+dfsg.orig.tar.xz 1a2f53fcbee5853f0e58da9406002237 34248 libs optional libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1.debian.tar.xz 117f57c5a99287ee5de4814260ec9257 10793 libs optional libxml2_2.9.14+dfsg-0.1+ubuntu22.04.1+deb.sury.org+1_source.buildinfo