forked from pool/expat
39c80d1cc4
- Update keyring automatically from keyserver during OBS service run. - Explicitly use --without-docbook (before it was implicit). - Include missing files for documentation and examples. - Add manpage for xmlwf, which is not available in the release tarball. - Clean the spec file a bit. - Update to 2.6.0: * Security fixes: - CVE-2023-52425 (boo#1219559) -- Fix quadratic runtime issues with big tokens that can cause denial of service, in partial where dealing with compressed XML input. Applications that parsed a document in one go -- a single call to functions XML_Parse or XML_ParseBuffer -- were not affected. The smaller the chunks/buffers you use for parsing previously, the bigger the problem prior to the fix. Backporters should be careful to no omit parts of pull request #789 and to include earlier pull request #771, in order to not break the fix. - CVE-2023-52426 (boo#1219561) -- Fix billion laughs attacks for users compiling *without* XML_DTD defined (which is not common). Users with XML_DTD defined have been protected since Expat >=2.4.0 (and that was CVE-2013-0340 back then). * Bug fixes: - Fix parse-size-dependent "invalid token" error for external entities that start with a byte order mark - Fix NULL pointer dereference in setContext via XML_ExternalEntityParserCreate for compilation with XML_DTD undefined - Protect against closing entities out of order OBS-URL: https://build.opensuse.org/request/show/1146279 OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/expat?expand=0&rev=106
17 lines
833 B
Plaintext
17 lines
833 B
Plaintext
-----BEGIN PGP SIGNATURE-----
|
|
|
|
iQIzBAABCAAdFiEEy43nCpDPv2w79cxWliYqz/vTrsYFAmXCZZsACgkQliYqz/vT
|
|
rsZ6Mw//QulqmE4mQwy52wl17LQocguoQTCueHs8XFsmAQr9HFgKjaKaLn4Cqqay
|
|
eHJryqsjK3hjjWZWC5VFwFYIYnfEJ9Xiw4s0S1tPSOUiO2+GM5djuNGK3xlEI3aI
|
|
e+h8WwK1FvhlkjpBBbbXvbHTHKqOv6k+jt5yPr0gArYZ3aG0L+1Ihuv8RYdWfc9n
|
|
e31jwZSO5zjuP/tZvK5DzVdrmx2RgLKlrFtx+fA26VOn5zMRdBFcB7gCCYxTepzW
|
|
GF0H6DP3uNA3MAZT69gFVZ5TiDwEkxBh7Lez3aiE1b6oYy7cxQ4aJmaiPgDM5JLk
|
|
/Vu4nz0RuSLXIKePHXiAvDcbWmvlAPdvDsc0INh71RXF5avK3n1XVPfo6UcxZ7Hl
|
|
K0WxqRGgM+zRHrbwnCRm897EaET6jQ+G3hSUAyIPvnO9WILZrWi+4WHdfRpuaL3j
|
|
saOrawJOiGi7A4x21KkS83PVDq1l8RE+TNlRVYS3/Z/nqgeqwCKG04u8Tn8bnfYV
|
|
WRpFyDRL6yds+pFZUObbiHyzXt17O/eMEZEIrg2HBafYJ1fUcf1wjPy0H/wZEdvo
|
|
itNKn8ZQ1U0kwl4v/P/+RHkgKcAq4ES7AKIOpgLhi8ilr5GdpSuC3in3Ag/Oand5
|
|
jd9g//FbD2y3KXY60UPgs43Vw5mjBUG/BAn8i+75nf2FQQ2cCIM=
|
|
=oqBM
|
|
-----END PGP SIGNATURE-----
|