Re: [ptxdist] [PATCH] libxml2: apply fix for CVE-2017-8872

2018-06-22 Thread Denis OSTERLAND
Am Freitag, den 22.06.2018, 09:15 +0200 schrieb Michael Olbrich: > > + > > +Origin: vendor, https://bugzilla.novell.com/attachment.cgi?id=732309 > > +Bug: https://bugzilla.gnome.org/show_bug.cgi?id=775200 > > +Bug-Debian: https://bugs.debian.org/862450 > > +Bug-Debian-Security: > >

Re: [ptxdist] [PATCH] libxml2: apply fix for CVE-2017-8872

2018-06-22 Thread Alexander Dahl
Hei hei, Am Freitag, 22. Juni 2018, 09:15:16 CEST schrieb Michael Olbrich: > That's an upstream patch, right? It should come before the other patch in > the 'upstream' section. I checked yesterday, it's not in libxml2 master, yet. See the libxml2 bugtracker for details:

Re: [ptxdist] [PATCH] libxml2: apply fix for CVE-2017-8872

2018-06-22 Thread Michael Olbrich
On Thu, Jun 21, 2018 at 11:25:03AM +, Denis OSTERLAND wrote: > Taken from debian buster libxml2_2.9.7+dfsg-1. > > Signed-off-by: Denis Osterland > --- > ...-bounds-read-in-htmlParseTryOrFinish.patch | 31 +++ > patches/libxml2-2.9.7/series | 5 +-- > 2

[ptxdist] [PATCH] libxml2: apply fix for CVE-2017-8872

2018-06-21 Thread Denis OSTERLAND
Taken from debian buster libxml2_2.9.7+dfsg-1. Signed-off-by: Denis Osterland --- ...-bounds-read-in-htmlParseTryOrFinish.patch | 31 +++ patches/libxml2-2.9.7/series | 5 +-- 2 files changed, 34 insertions(+), 2 deletions(-) create mode 100644