Format: 1.8 Date: Tue, 14 Mar 2017 16:06:13 -0400 Source: libxml2 Binary: libxml2 libxml2-utils libxml2-utils-dbg libxml2-dev libxml2-dbg libxml2-doc python-libxml2 python-libxml2-dbg libxml2-udeb Architecture: i386 Version: 2.9.3+dfsg1-1ubuntu0.2 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: libxml2 - GNOME XML library libxml2-dbg - Debugging symbols for the GNOME XML library libxml2-dev - Development files for the GNOME XML library libxml2-doc - Documentation for the GNOME XML library libxml2-udeb - GNOME XML library - minimal runtime (udeb) libxml2-utils - XML utilities libxml2-utils-dbg - XML utilities (debug extension) python-libxml2 - Python bindings for the GNOME XML library python-libxml2-dbg - Python bindings for the GNOME XML library (debug extension) Launchpad-Bugs-Fixed: 1652325 Changes: libxml2 (2.9.3+dfsg1-1ubuntu0.2) xenial-security; urgency=medium . * SECURITY UPDATE: format string vulnerabilities - debian/patches/CVE-2016-4448-1.patch: fix format string warnings in HTMLparser.c, SAX2.c, catalog.c, configure.ac, debugXML.c, encoding.c, entities.c, error.c, include/libxml/parserInternals.h, include/libxml/xmlerror.h, include/libxml/xmlstring.h, libxml.h, parser.c, parserInternals.c, relaxng.c, schematron.c, testModule.c, valid.c, xinclude.c, xmlIO.c, xmllint.c, xmlreader.c, xmlschemas.c, xmlstring.c, xmlwriter.c, xpath.c, xpointer.c. - debian/patches/CVE-2016-4448-2.patch: fix format string warnings in libxml.h, relaxng.c, xmlschemas.c, xmlstring.c. - debian/libxml2.symbols: added new symbol. - CVE-2016-4448 * SECURITY UPDATE: use-after-free via namespace nodes in XPointer ranges - debian/patches/CVE-2016-4658.patch: disallow namespace nodes in XPointer ranges in xpointer.c. - CVE-2016-4658 * SECURITY UPDATE: use-after-free in XPointer range-to function - debian/patches/CVE-2016-5131-1.patch: fix XPointer paths beginning with range-to in xpath.c, xpointer.c. - debian/patches/CVE-2016-5131-2.patch: fix comparison with root node in xmlXPathCmpNodes in xpath.c. - CVE-2016-5131 * debian/patches/lp1652325.patch: XML push parser fails with bogus UTF-8 encoding error when multi-byte character in large CDATA section is split across buffer (LP: #1652325) Checksums-Sha1: 45698eb3bdb5799f8a4743ead707e9854132baae 1463154 libxml2-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb d2d34984162c0babe5147927734d8ff89778639b 1062 libxml2-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb e7602e461f23f9ae5121c00c8d0300f16b95f51b 1062 libxml2-dev-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb 5b76f11b4343f32371d6cfc9f3d40522c4d24b4d 805036 libxml2-dev_2.9.3+dfsg1-1ubuntu0.2_i386.deb 89add3dc666bbe869573db3494d2d1a9dcd5c6ef 1054 libxml2-udeb-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb ac0cd70600e8170ec6f02fad7f7cfde56a824bcf 667580 libxml2-udeb_2.9.3+dfsg1-1ubuntu0.2_i386.udeb 003ba87bdf80c6cc86d3b5e34b66291a21286c04 66498 libxml2-utils-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb 8a8c4eba4491c45e2a436e0b7b028b2e98693b4c 1090 libxml2-utils-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb ca43afd00744efd2c2aa8726a3ebe53aaa9dffb8 35750 libxml2-utils_2.9.3+dfsg1-1ubuntu0.2_i386.deb 158f8d397b5cf6cb0bc3fe5d70d740747e32d7bc 731944 libxml2_2.9.3+dfsg1-1ubuntu0.2_i386.deb 76678da65289eb764defbf57cfbab3d56f39f0ce 218792 python-libxml2-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb 2edd90727bb6efa8719e6603ee96569ce8be3e1a 138610 python-libxml2_2.9.3+dfsg1-1ubuntu0.2_i386.deb Checksums-Sha256: e63ec77d4d5945638753c3dcd14e72509f989636d9dcace6ecf1a17e8b8bbe02 1463154 libxml2-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb 0651c5dc4696bd472e0dcadcb271bd660e60f63b2d2ab8d426f85bba8a9a5918 1062 libxml2-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb 194a35d302b1b57a3e93a70da2af501c5a3d2b7b93da21e4182b6a547aec5d9f 1062 libxml2-dev-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb a159befab65c51e9cd66aad6c3b261bd371fbde89545254c6ab225da534ec50d 805036 libxml2-dev_2.9.3+dfsg1-1ubuntu0.2_i386.deb d88a857b9446f7a535bddbff5bd4db092fdec7bebb5336a8049551bcd08e7602 1054 libxml2-udeb-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb fefea1cf68aa48bf933e25f1dd9a2ea78cdebef4f42cbf49bccf76740ed6f842 667580 libxml2-udeb_2.9.3+dfsg1-1ubuntu0.2_i386.udeb dff2a6b5678cea696cf43ee0d6bfa1acebdd5e572d0f54d14d2e6ccefa59eef4 66498 libxml2-utils-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb e86144b029d27bd63c2d7a2448f020ad777bcba97f196329c0d095a8e67a1050 1090 libxml2-utils-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb 22c48fc9d0cd01012d89a5d794f975ca642ac17f644d1099325f7d99423f563d 35750 libxml2-utils_2.9.3+dfsg1-1ubuntu0.2_i386.deb 57c1f6598143713dee9c393c76866d53997ea428413423ab6a8b51607d3cde9a 731944 libxml2_2.9.3+dfsg1-1ubuntu0.2_i386.deb 971a1bc00918506c6f8fd94e96622bfbbb4dde2b8af7e8ef8828e60132fcb9f2 218792 python-libxml2-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb 8465dbdf756b4e5dd53faabf24de0bc8354d7c0c849c8b2850cb860cbbcdaa45 138610 python-libxml2_2.9.3+dfsg1-1ubuntu0.2_i386.deb Files: fa9b1a99857142f24d3911b1db22c980 1463154 debug extra libxml2-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb 7cc5c2f34ba04dcf2f4f73878c669ae1 1062 libs extra libxml2-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb e73fe273cbf0d5404a5dc1c23bf7c072 1062 libdevel extra libxml2-dev-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb 3a87379b2ef4cf8a81854ec8be04b9cf 805036 libdevel optional libxml2-dev_2.9.3+dfsg1-1ubuntu0.2_i386.deb 95837048c289da76fec64ffab635cd49 1054 debian-installer extra libxml2-udeb-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb 5f3c3d89c0a1905bad3e7f5ff134d678 667580 debian-installer optional libxml2-udeb_2.9.3+dfsg1-1ubuntu0.2_i386.udeb d335570fbc1f10debf6e87dfe58a6833 66498 debug extra libxml2-utils-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb b617bc15979a0349e875f122eb1db332 1090 text extra libxml2-utils-dbgsym_2.9.3+dfsg1-1ubuntu0.2_i386.ddeb 10ce874765329c4efa1b10651b4cb0dc 35750 text optional libxml2-utils_2.9.3+dfsg1-1ubuntu0.2_i386.deb eb4e2a46cac7788e7b204c3454397fff 731944 libs standard libxml2_2.9.3+dfsg1-1ubuntu0.2_i386.deb 59918ab15721a5293717b848eea2756f 218792 debug extra python-libxml2-dbg_2.9.3+dfsg1-1ubuntu0.2_i386.deb bff530a3409621029faf20981e8b02f2 138610 python optional python-libxml2_2.9.3+dfsg1-1ubuntu0.2_i386.deb Original-Maintainer: Debian XML/SGML Group Package-Type: udeb