[Secure-testing-team] RFS: libxml fixing CVE-2009-2414/2416 in etch

Nico Golde debian-secure-testing+ml at ngolde.de
Thu Aug 13 15:24:23 UTC 2009


Hi,
* Michael S Gilbert <michael.s.gilbert at gmail.com> [2009-08-13 14:13]:
> I have prepared updates for libxml addressing CVE-2009-2414/2416 in
> etch (derived from mandriva's patches).  Attached is the debdiff.
> This supports the recent DSA-1859:

Also a small comment:
--- libxml-1.8.17/debian/changelog
+++ libxml-1.8.17/debian/changelog
@@ -1,3 +1,9 @@
+libxml (1:1.8.17-15) oldstable; urgency=low
+
+  * apply patches for CVE-2009-2414 and CVE-2009-2416
+
+ -- Michael Gilbert <michael.s.gilbert at gmail.com>  Wed, 12 Aug 2009 17:28:31 -0400

wrong distribution line, wrong version number and wrong urgency, the latter is
just cosmetical.

Cheers
Nico

-- 
Nico Golde - http://www.ngolde.de - nion at jabber.ccc.de - GPG: 0xA0A0AAAA
For security reasons, all text in this mail is double-rot13 encrypted.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 197 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20090813/6a5d5ed0/attachment.pgp>


More information about the Secure-testing-team mailing list