From a408f395abbbc204b97f242a606bb9735752ba91 Mon Sep 17 00:00:00 2001 From: Franco Fichtner Date: Tue, 17 Sep 2019 08:30:42 +0200 Subject: [PATCH] security/vuxml: sync with upstream Taken from: HardenedBSD --- security/vuxml/vuln.xml | 32 +++++++++++++++++++++++++++++++- 1 file changed, 31 insertions(+), 1 deletion(-) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 6ddca139888..6ad993fa942 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,36 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + expat2 -- Fix extraction of namespace prefixes from XML names + + + expat + 2.2.7 + + + + +

expat project reports:

+
+

+ XML names with multiple colons could end up in the + wrong namespace, and take a high amount of RAM and CPU + resources while processing, opening the door to + use for denial-of-service attacks +

+
+ +
+ + https://github.com/libexpat/libexpat/blob/R_2_2_7/expat/Changes + + + 2019-06-19 + 2019-09-16 + +
+ curl -- multiple vulnerabilities @@ -124,7 +154,7 @@ Notes: openssl - 1.0.2t + 1.0.2t,1 openssl111