165 Commits

Author SHA256 Message Date
3f2db54b5c Accepting request 1330962 from home:pgajdos
security update

OBS-URL: https://build.opensuse.org/request/show/1330962
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=258
2026-02-09 08:48:10 +00:00
c06dd8a292 Accepting request 1328521 from home:dgarcia:branches:devel:libraries:c_c++
- Add patch libxml2-CVE-2026-0989.patch, to fix call stack exhaustion
  leading to application crash due to RelaxNG parser not limiting the
  recursion depth when resolving `<include>` directives
  CVE-2026-0989, bsc#1256805, https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374

OBS-URL: https://build.opensuse.org/request/show/1328521
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=256
2026-01-22 11:00:53 +00:00
8c69309235 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=253
2025-09-12 08:54:19 +00:00
d1a5c175f2 Accepting request 1302350 from home:pgajdos:libxml2
- version update to 2.14.5
  2.14.0
  ** Major changes **
  o The HTML tokenizer now conforms fully to HTML5.
  o Binary compatibility is restricted to versions 2.14 or newer.
    The soname was bumped from libxml2.so.2 to libxml2.so.16.
  o The serialization API will now take user-provided or default
    encodings into account when serializing attribute values.
  o The XML parser won't try to merge consecutive CDATA sections
    as before to align with web standards.
  o Support for RELAX NG can now be disabled with a new configuration
    option independently of XML Schemas support.
  o The "legacy" configuration option won't enable support for HTTP
    and LZMA anymore. 
  o Parts of the xmllint executable were refactored, allowing the
    combination of more options.
  o Meson is fully supported now.
  o Parts of the buffering code were reworked and simplified.
  o Overflow checks before reallocations were hardenend.
  o Some unprefixed symbols were renamed to avoid namespace pollution.
  ** New features **
  o Input callbacks can now be set on a parser context and an improved
    API to create parser input is available.
  o The following new functions, taking a parser input object, were added:
    . xmlCtxtParseDocument
    . xmlCtxtParseContent
    . xmlCtxtParseDtd
  o The xmlSave API now has additional options to replace global settings.
  o Parser options XML_PARSE_UNZIP, XML_PARSE_NO_SYS_CATALOG and
    XML_PARSE_CATALOG_PI were added.

OBS-URL: https://build.opensuse.org/request/show/1302350
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=252
2025-09-09 08:15:17 +00:00
ba5525176c checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=250
2025-07-18 12:49:45 +00:00
e479a4b3c3 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=248
2025-07-07 12:23:45 +00:00
e5b25e2ee1 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=247
2025-07-01 10:08:47 +00:00
81009171e8 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=246
2025-06-26 12:54:45 +00:00
2413995e43 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=244
2025-06-18 08:10:06 +00:00
a4c40d05cb checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=242
2025-04-22 13:40:22 +00:00
a4a93a5a47 Accepting request 1270607 from home:iznogood:branches:devel:libraries:c_c++
- Update to version 2.13.8:
  + Security:
    - [CVE-2025-32415] schemas: Fix heap buffer overflow in
      xmlSchemaIDCFillNodeTables.
    - [CVE-2025-32414] python: Read at most len/4 characters.

OBS-URL: https://build.opensuse.org/request/show/1270607
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=241
2025-04-22 08:35:55 +00:00
28686d76c3 Accepting request 1265279 from home:iznogood:branches:devel:libraries:c_c++
- Update to version 2.13.7:
  + Regressions:
    - tree: Fix xmlTextMerge with NULL args
    - io: Fix `compressed` flag for uncompressed stdin
    - parser: Fix parsing of DTD content

OBS-URL: https://build.opensuse.org/request/show/1265279
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=239
2025-03-31 08:31:23 +00:00
a1a7df1c4d checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=237
2025-02-20 13:14:47 +00:00
14feb04626 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=236
2025-02-20 11:45:37 +00:00
384c309eaa checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=235
2025-02-20 11:09:54 +00:00
977e925b90 Accepting request 1246806 from home:iznogood:branches:devel:libraries:c_c++
New upstream release

OBS-URL: https://build.opensuse.org/request/show/1246806
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=234
2025-02-20 11:08:50 +00:00
60478ade38 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=232
2025-01-29 08:27:09 +00:00
5674c3f847 Accepting request 1238553 from home:pmonrealgonzalez:branches:devel:libraries:c_c++
- Update to 2.13.5:
  * Regressions:
    - xmlIO: Fix reading from non-regular files like pipes
    - xmlreader: Fix return value of xmlTextReaderReadString
    - parser: Fix loading of parameter entities in external DTDs
    - parser: Fix downstream code that swaps DTDs
    - parser: Fix detection of duplicate attributes
    - string: Fix va_copy fallback
  * Bug fixes:
    - xpath: Fix parsing of non-ASCII names
- Update to 2.13.4:
  * Regressions:
    - parser: Make unsupported encodings an error in declarations
    - io: don't set the executable bit when creating files
    - xmlcatalog: Improved fix for #699
    - Revert "catalog: Fetch XML catalog before dumping"
    - io: Add missing calls to xmlInitParser
    - tree: Restore return value of xmlNodeListGetString with NULL list
    - parser: Fix error handling after reaching limit
    - parser: Make xmlParseChunk return an error if parser was stopped
  * Bug fixes:
    - python: Fix SAX driver with character streams
  * Improvements:
    - xpath: Make recursion check work with xmlXPathCompile
    - parser: Report at least one fatal error
- Update to 2.13.3:
  * Security:
    - [bsc#1234812, CVE-2024-40896] Fix XXE protection in downstream code
  * Regressions:
    - autotools: Use AC_CHECK_DECL to check for getentropy

OBS-URL: https://build.opensuse.org/request/show/1238553
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=230
2025-01-20 08:42:54 +00:00
203e911a78 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=228
2024-11-13 10:54:56 +00:00
f0da44cf77 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=227
2024-11-13 09:48:33 +00:00
6e2d0b12d0 checkin
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=225
2024-11-12 14:57:39 +00:00
d6f95e6a17 Accepting request 1189639 from home:iznogood:branches:devel:libraries:c_c++
- Update to version 2.12.9:
  + Security: (CVE-2024-40896) Fix XXE protection in downstream
    code.
  + Improvements: Undeprecate xmlKeepBlanksDefault.

OBS-URL: https://build.opensuse.org/request/show/1189639
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=223
2024-08-01 15:03:59 +00:00
15e6c029a4 Accepting request 1183474 from home:david.anes:branches:devel:libraries:c_c++
+ Fix buffer overread with `xmllint --htmlout` (CVE-2024-34459, bsc#1224282).

OBS-URL: https://build.opensuse.org/request/show/1183474
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=221
2024-06-26 16:35:38 +00:00
c8616a516d Accepting request 1183471 from home:david.anes:branches:devel:libraries:c_c++
+ Fix buffer overread with `xmllint --htmlout` (CVE-2024-34459, bsc#2280532).

OBS-URL: https://build.opensuse.org/request/show/1183471
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=220
2024-06-26 16:32:51 +00:00
ff5b3b3260 Accepting request 1180179 from home:dimstar:Factory
- Update to version 2.12.8:
  + parser: Fix performance regression when parsing namespaces.

OBS-URL: https://build.opensuse.org/request/show/1180179
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=218
2024-06-12 13:37:18 +00:00
3ca89bdd84 Accepting request 1173926 from home:dimstar:Factory
- Update to version 2.12.7:
  + Fix buffer overread with `xmllint --htmlout` (CVE-2024-34459).
  + xmllint: Fix --pedantic option.
  + save: Handle invalid parent pointers in xhtmlNodeDumpOutput.

OBS-URL: https://build.opensuse.org/request/show/1173926
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=216
2024-05-15 12:25:59 +00:00
ad29b14b81 Accepting request 1168664 from home:mathletic:branches:devel:libraries:c_c++
- Update to version 2.12.6
  * Regressions
    - parser: Fix detection of duplicate attributes in XML namespace
    - xmlreader: Fix xmlTextReaderConstEncoding
    - html: Fix htmlCreatePushParserCtxt with encoding
    - xmllint: Return error code if XPath returns empty nodeset
- Update to version 2.12.5
  * Security
    - [CVE-2024-25062] xmlreader: Don't expand XIncludes when backtracking
  * Regressions
    - parser: Fix crash in xmlParseInNodeContext with HTML documents
- Update to version 2.12.4
  * Regressions
   - parser: Fix regression parsing standalone declarations
   - autotools: Readd --with-xptr-locs configuration option
   - parser: Fix build --without-output
   - parser: Don't grow or shrink pull parser memory buffers
   - io: Fix memory lifetime issue with input buffers
- Update to version 2.12.3
  * Regressions
    - parser: Fix namespaces redefined from default attributes
  * Build fixes
    - include: Rename XML_EMPTY helper macro
    - include: Move declaration of xmlInitGlobals
    - include: Add missing includes
    - include: Move globals from xmlsave.h to parser.h
    - include: Readd circular dependency between tree.h and parser.h
- Drop libxml2-CVE-2024-25062.patch as it is part of upstream

OBS-URL: https://build.opensuse.org/request/show/1168664
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=214
2024-04-18 07:10:40 +00:00
55b6381927 Accepting request 1145592 from home:david.anes:branches:devel:libraries:c_c++
- Security fix (CVE-2024-25062, bsc#1219576) use-after-free in XMLReader
  * Added libxml2-CVE-2024-25062.patch

OBS-URL: https://build.opensuse.org/request/show/1145592
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=212
2024-02-10 12:10:37 +00:00
31515762f1 Accepting request 1132279 from home:iznogood:factory
- Update to version 2.12.2:
  * Regressions:
    - parser:
      . Fix invalid free in xmlParseBalancedChunkMemoryRecover
      . Make CRLF increment line number
    - globals: Disable TLS in static Windows builds
    - html: Reenable buggy detection of XML declarations
    - tree: Fix regression when copying DTDs
  * Build fixes
    - build: Disable compiler TLS by default
    - cmake: Update config.h.cmake.in
    - tests: Fix tests --with-valid --without-xinclude

OBS-URL: https://build.opensuse.org/request/show/1132279
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=211
2023-12-12 12:56:26 +00:00
f1c4a97857 Accepting request 1128650 from home:iznogood:branches:devel:libraries:c_c++
New stable release.
Also remove whitespaces from .changes

OBS-URL: https://build.opensuse.org/request/show/1128650
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=210
2023-11-27 09:03:56 +00:00
3fc779bce8 Accepting request 1127259 from home:david.anes:branches:devel:libraries:c_c++
OBS-URL: https://build.opensuse.org/request/show/1127259
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=208
2023-11-17 09:12:32 +00:00
887ff20d64 Accepting request 1126959 from home:david.anes:branches:devel:libraries:c_c++
- Bring back a patch that was mistakenly removed in the last update.
  * Readded libxml2-make-XPATH_MAX_NODESET_LENGTH-configurable.patch

OBS-URL: https://build.opensuse.org/request/show/1126959
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=207
2023-11-16 15:56:37 +00:00
d82c209a7d Accepting request 1126893 from home:david.anes:branches:devel:libraries:c_c++
- Removed patches (already in upstream):
  * libxml2-CVE-2023-39615.patch
  * libxml2-CVE-2023-45322.patch
  * libxml2-make-XPATH_MAX_NODESET_LENGTH-configurable.patch
  * python312.patch
- Update to 2.12.0: 
  * Major changes:
    - Most of the known issues leading to quadratic behavior in the 
      XML parser were fixed. Internal hash tables were rewritten to 
      reduce memory consumption.
    - Starting with this release, it should be enough to add the 
      --with-legacy configuration option to provide maximum ABI 
      compatibility. 
    - libxml2 will now store global variables in thread-local 
      storage if supported by the compiler. This avoids allocating 
      the data lazily which can result in a fatal error condition. 
    - A new API function xmlCheckThreadLocalStorage was added so the
      allocation can be checked earlier if compiler TLS is not 
      supported. 
    - To prepare for future improvements, some API functions now 
      expect or return a const xmlError struct.
    - Several cyclic dependencies in public header files were fixed. 
    - Refactoring of the encoding code has been mostly completed. 
      Calling xmlSwitchEncoding from client code is now fully 
      supported, for example to override the encoding for the push 
      parser.
    - When parsing data from memory, libxml2 will now stream data 
      chunk by chunk instead of copying the whole buffer (possibly 
      twice with encodings), reducing peak memory consumption 
      considerably.

OBS-URL: https://build.opensuse.org/request/show/1126893
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=206
2023-11-16 15:42:22 +00:00
4903181851 Accepting request 1126868 from home:iznogood:branches:devel:libraries:c_c++
- Update to version 2.11.6:
  * Regressions:
    - threads: Fix --with-thread-alloc
    - xinclude: Fix ‘last’ pointer in xmlXIncludeCopyNode
  * Bug fixes: parser: Fix potential use-after-free in
    xmlParseCharDataInternal

OBS-URL: https://build.opensuse.org/request/show/1126868
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=205
2023-11-16 13:01:40 +00:00
a31cc244fa Accepting request 1125681 from home:david.anes:branches:devel:libraries:c_c++
- Security fix: CVE-2023-45322 (bsc#1216129)
  * use-after-free in xmlUnlinkNode() in tree.c
  * Added file libxml2-CVE-2023-45322.patch

OBS-URL: https://build.opensuse.org/request/show/1125681
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=203
2023-11-13 17:08:33 +00:00
985d7f09a9 Accepting request 1119767 from home:dgarcia:branches:devel:libraries:c_c++
- Add python312.patch to make it compatible with python 3.12
  https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/226
- Use pyproject_wheel and pyproject_install macros instead of
  python_build, python_install
- Security fix: CVE-2023-39615 (bsc#1214768)
  * crafted xml can cause global buffer overflow
  * Added file libxml2-CVE-2023-39615.patch

OBS-URL: https://build.opensuse.org/request/show/1119767
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=201
2023-10-24 07:38:21 +00:00
OBS User buildservice-autocommit
e742d98d05 Updating link to change in openSUSE:Factory/libxml2 revision 119
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=11b27c1353a1b77ade1f37aa6a845c25
2023-09-04 11:19:30 +00:00
ff6d2c2613 Accepting request 1103190 from home:iznogood:branches:devel:libraries:c_c++
- Update to version 2.11.5:
  + Regressions:
    - parser: Make xmlSwitchEncoding always skip the BOM
    - autotools: Improve iconv check
  + Bug fixes:
    - valid: Fix c1->parent pointer in xmlCopyDocElementContent
    - encoding: Always call ucnv_convertEx with flush set to false
  + Portability: autotools: fix Python module file ext for
    cygwin/msys2
  + Tests: runtest: Fix compilation without LIBXML_HTML_ENABLED

OBS-URL: https://build.opensuse.org/request/show/1103190
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=200
2023-08-16 13:07:29 +00:00
813cb5bfcb Accepting request 1087943 from home:iznogood:branches:devel:libraries:c_c++
- Update to version 2.11.4:
  + Fixes a serious regression: parser: Fix regression when push
    parsing UTF-8 sequences.

OBS-URL: https://build.opensuse.org/request/show/1087943
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=199
2023-05-23 08:05:07 +00:00
3a929e78e1 Accepting request 1086546 from home:iznogood:factory
- Update to version 2.11.3:
  + xinclude: Fix false positives in inclusion loop detection.
  + autotools: Fix ICU detection.
  + parser: Fix "huge input lookup" error with push parser.
  + xpath: Fix build without LIBXML_XPATH_ENABLED.
  + hash: Fix possible startup crash with old libxslt versions.
  + autoconf: fix iconv library paths.

OBS-URL: https://build.opensuse.org/request/show/1086546
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=198
2023-05-11 15:53:54 +00:00
14ec02b261 Accepting request 1085154 from home:iznogood:factory
- Update to version 2.11.2:
  + Fix regressions:
    - threads: Fix startup crash with weak symbol hack
    - win32: Don’t depend on removed .def file
    - schemas: Fix memory leak in xmlSchemaValidateStream

OBS-URL: https://build.opensuse.org/request/show/1085154
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=197
2023-05-08 13:18:07 +00:00
cb59dd3915 Accepting request 1084549 from home:david.anes:branches:devel:libraries:c_c++
* See the full changelog at https://discourse.gnome.org/t/libxml2-2-11-0-released/15123

OBS-URL: https://build.opensuse.org/request/show/1084549
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=196
2023-05-04 07:36:20 +00:00
fa86affcb3 * libxml2-python3-unicode-errors.patch
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=195
2023-05-03 16:01:55 +00:00
0b3afb1a8d Accepting request 1084343 from home:david.anes:branches:devel:libraries:c_c++
- Rebased patches:
  * libxml2-make-XPATH_MAX_NODESET_LENGTH-configurable.patch
- Update to 2.11.1:
  * Fixes build and ABI issues.
    - cmake: Fix va_copy detection (Luca Niccoli)
    - libxml.m4: Fix quoting
    - Link with --undefined-version
    - libxml2.syms: Revert removal of version information
- Update to 2.11.0: 
  * Major changes
    - Protection against entity expansion attacks, also known as 
      "billion laughs" has been greatly improved. Malicious files 
      should be detected reliably now and false positives should be
      reduced. It is possible though that large documents which make
      heavy use of entities are rejected now.
    - This release finally fixes symbol visibility on UNIX systems. 
      Internal symbols will now be hidden. While these symbols were
      never declared in public headers, it was still possible to
      declare them manually. Now this won't work.
    - All symbol information has been removed from the ELF version
      script to fix link errors with --no-undefined-version. The
      version nodes are kept so it should still be possible to run
      binaries linked against older versions.
    - About 90 memory errors in code paths handling malloc failures
      have been fixed. While these issues shouldn't impact security,
      this improves robustness under memory pressure.
    - The XInclude engine has been reworked to properly support 
      nested includes.
    - Several cases of quadratic behavior in the XML push parser
      have been fixed.

OBS-URL: https://build.opensuse.org/request/show/1084343
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=194
2023-05-03 16:01:24 +00:00
30e5741743 Accepting request 1082112 from home:david.anes:branches:devel:libraries:c_c++
- Remove unneeded dependency (bsc#1209918).

OBS-URL: https://build.opensuse.org/request/show/1082112
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=192
2023-04-25 10:32:39 +00:00
63882702eb Accepting request 1079408 from home:david.anes:branches:home:iznogood:branches:devel:libraries:c_c++
- Update to version 2.10.4:
  + Security:
    - [CVE-2023-29469, bsc#1210412] Hashing of empty dict strings 
      isn’t deterministic
    - [CVE-2023-28484, bsc#1210411] Fix null deref in 
      xmlSchemaFixupComplexType
    - schemas: Fix null-pointer-deref in
      xmlSchemaCheckCOSSTDerivedOK
  + Regressions:
    - SAX2: Ignore namespaces in HTML documents
    - io: Fix “buffer full” error with certain buffer sizes

OBS-URL: https://build.opensuse.org/request/show/1079408
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=190
2023-04-14 09:06:26 +00:00
5531ecc63c Accepting request 1062410 from home:dirkmueller:Factory
- remove zlib-devel, pkgconfig(zlib) is sufficient

OBS-URL: https://build.opensuse.org/request/show/1062410
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=188
2023-02-06 05:24:41 +00:00
44772b3ca8 Accepting request 1032566 from home:david.anes:branches:devel:libraries:c_c++
- Add W3C conformance tests to the testsuite (bsc#1204585):
  * Added file xmlts20080827.tar.gz

OBS-URL: https://build.opensuse.org/request/show/1032566
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=186
2022-10-31 18:19:13 +00:00
20854f0f12 - Update to version 2.10.3 (bsc#1204366, CVE-2022-40303, bsc#1204367, CVE-2022-40304):
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=184
2022-10-17 13:44:07 +00:00
17ec2d25dc Accepting request 1010960 from home:iznogood:branches:devel:libraries:c_c++
- Update to version 2.10.3:
  + Security:
    - [CVE-2022-40304] Fix dict corruption caused by entity
      reference cycles
    - [CVE-2022-40303] Fix integer overflows with XML_PARSE_HUGE
    - Fix overflow check in SAX2.c
  + Build system: cmake: Set SOVERSION
- Rebase patches with quilt.

OBS-URL: https://build.opensuse.org/request/show/1010960
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libxml2?expand=0&rev=183
2022-10-17 07:34:17 +00:00