[libxml2] Created tag v2.9.4



The signed tag 'v2.9.4' was created.

Tagger: Daniel Veillard <veillard redhat com>
Date: Mon May 23 16:06:06 2016 +0800

    Release of libxml2-2.9.4

Changes since the last tag 'CVE-2016-1834':

Daniel Veillard (5):
      Add more debugging info to runtest
      Avoid an out of bound access when serializing malformed strings
      Fix inappropriate fetch of entities content
      Avoid building recursive entities
      Release of libxml2-2.9.4

David Kilzer (7):
      Integer signed/unsigned type mismatch in xmlParserInputGrow()
      Implement "runtest -u" mode
      Unsigned addition may overflow in xmlMallocAtomicLoc()
      Bug 758588: Heap-based buffer overread in xmlParserPrintFileContextInternal 
<https://bugzilla.gnome.org/show_bug.cgi?id=758588>
      Fix some format string warnings with possible format string vulnerability
      Heap-based buffer-underreads due to xmlParseName
      More format string warnings with possible format string vulnerability

Hugh Davenport (1):
      Detect change of encoding when parsing HTML names

Mattias Hansson (2):
      Revert the use of SAVE_LDFLAGS in configure.ac
      Correct the usage of LDFLAGS

Mike Frysinger (1):
      libxml2 hardcodes -L/lib in zlib/lzma tests which breaks cross-compiles

Pranjal Jumde (6):
      Bug 757711: heap-buffer-overflow in xmlFAParsePosCharGroup 
<https://bugzilla.gnome.org/show_bug.cgi?id=757711>
      Bug 758605: Heap-based buffer overread in xmlDictAddString 
<https://bugzilla.gnome.org/show_bug.cgi?id=758605>
      Bug 759398: Heap use-after-free in xmlDictComputeFastKey 
<https://bugzilla.gnome.org/show_bug.cgi?id=759398>
      Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral
      Heap use-after-free in xmlSAX2AttributeNs
      Heap-based buffer overread in htmlCurrentChar


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]