| abstract
| - libxml2-wa Gnome dè XML laibrari, yutilitis für prosesiŋ XML fayls wiŧ Python. XML is a metalanguage to let you design your own markup language. A regular markup language defines a way to describe information in a certain class of documents (eg HTML). XML lets you define your own customized markup languages for many classes of document. It can do this because it's written in SGML, the international standard metalanguage for markup languages. This package provides a library providing an extensive API to handle such XML data files. Jigùm-dè vörçion-wa 2.9.3+dfsg1-1ubuntu0.1, wiŧin ùpdeits folowen:
* SECURITY UPDATE: heap-based buffer overread in xmlNextChar
* debian/patches/CVE-2016-1762.patch: return after error in parser.c.
* SECURITY UPDATE: heap-based buffer overread in htmlCurrentChar
* debian/patches/CVE-2016-1833.patch: fix tests in parserInternals.c.
* SECURITY UPDATE: heap-buffer-overflow in xmlStrncat
* debian/patches/CVE-2016-1834.patch: check for negative lengths in xmlstring.c.
* SECURITY UPDATE: heap use-after-free in xmlSAX2AttributeNs
* debian/patches/CVE-2016-1835.patch: add check to parser.c, add tests to result/errors/759020.xml.err, result/errors/759020.xml.str, test/errors/759020.xml.
* SECURITY UPDATE: heap use-after-free in xmlDictComputeFastKey
* debian/patches/CVE-2016-1836.patch: prevent stale pointer usage in parser.c, added tests to result/errors/759398.xml.err, result/errors/759398.xml.str, test/errors/759398.xml.
* SECURITY UPDATE: heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral
* debian/patches/CVE-2016-1837.patch: prevent stable pointer usage in HTMLparser.c
* SECURITY UPDATE: heap-based buffer overread in xmlParserPrintFileContextInternal
* debian/patches/CVE-2016-1838.patch: add bounds check to parser.c, add tests to result/errors/758588.xml.err, result/errors/758588.xml.str, test/errors/758588.xml.
* SECURITY UPDATE: heap-based buffer overread in xmlDictAddString
* debian/patches/CVE-2016-1839.patch: add bounds check to HTMLparser.c
* SECURITY UPDATE: heap-buffer-overflow in xmlFAParsePosCharGroup
* error in xmlregexp.c.
* SECURITY UPDATE: avoid building recursive entities
* debian/patches/CVE-2016-3627.patch: properly handle recursion in parser.c, tree.c.
* SECURITY UPDATE: recursion depth counter issue
* debian/patches/CVE-2016-3705.patch: properly could recursion depth in parser.c.
* SECURITY UPDATE: heap-based buffer-underreads due to xmlParseName
* debian/patches/CVE-2016-4447.patch: improve error handling in parser.c.
* SECURITY UPDATE: inappropriate fetch of entities content
* debian/patches/CVE-2016-4449.patch: fix another external entity fetch in parser.c.
* SECURITY UPDATE: out of bound access when serializing malformed strings
* debian/patches/CVE-2016-4483.patch: improve string handling in xmlsave.c.
|