Bug#602609: [xml/sgml-pkgs] Bug#602609: CVE-2010-4008: does not well process a malformed XPATH

2010-11-11 Thread Julien Cristau
On Sat, Nov 6, 2010 at 15:49:00 +0100, Mike Hommey wrote: Anyways, that would need a backport for stable, and maybe testing, depending how the release team feels about 2.7.8. 2.7.8-1 unblocked. Cheers, Julien signature.asc Description: Digital signature

Bug#602609: CVE-2010-4008: does not well process a malformed XPATH

2010-11-06 Thread Giuseppe Iuculano
Package: libxml2 Version: 2.7.7.dfsg-4 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, it was discovered that libxml2 does not well process a malformed XPATH, causing crash and allowing arbitrary code execution. Patch:

Bug#602609: [xml/sgml-pkgs] Bug#602609: CVE-2010-4008: does not well process a malformed XPATH

2010-11-06 Thread Mike Hommey
On Sat, Nov 06, 2010 at 02:22:18PM +0100, Giuseppe Iuculano wrote: Package: libxml2 Version: 2.7.7.dfsg-4 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, it was discovered that libxml2 does not well process a malformed XPATH, causing crash and