Bug#765722: CVE-2014-3660 libxml2 billion laugh variant

2014-11-08 Thread Lucas Nussbaum
Hi, I looked at this bug (kind-of randomly looking through RC bugs). The current status is: - fixed in unstable with a new upstream version - that new upstream version was aged/2 - however, an RC bug (#766884) was found in that new upstream version - in the upstream bug[1] for #766884, the

Bug#765722: [xml/sgml-pkgs] Bug#765722: CVE-2014-3660 libxml2 billion laugh variant

2014-10-25 Thread Aron Xu
Hi, I'm preparing 2.9.2 for jessie, and for stable/oldstable I'll work on them after the upload of 2.9.2. Thanks, Aron -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#765722: CVE-2014-3660 libxml2 billion laugh variant

2014-10-17 Thread Thijs Kinkhorst
Package: libxml2 Severity: serious Tags: security patch Hi, The Netherlands Cyber Security Center announced an issue in libxml2. https://www.ncsc.nl/actueel/nieuwsberichten/kwetsbaarheid-ontdekt-in-libxml2.html It seems to be a variant of the classic 'billion laughs' vulnerability. Upstream has