Format: 1.8 Date: Mon, 17 May 2021 18:13:47 -0400 Source: libxml2 Binary: libxml2 libxml2-dev libxml2-utils python3-libxml2 python3-libxml2-dbg Built-For-Profiles: noudeb Architecture: s390x Version: 2.9.10+dfsg-6.3ubuntu0.1 Distribution: hirsute Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Avital Ostromich Description: libxml2 - GNOME XML library libxml2-dev - Development files for the GNOME XML library libxml2-utils - XML utilities python3-libxml2 - Python3 bindings for the GNOME XML library python3-libxml2-dbg - Python3 bindings for the GNOME XML library (debug extension) Changes: libxml2 (2.9.10+dfsg-6.3ubuntu0.1) hirsute-security; urgency=medium . * SECURITY UPDATE: use-after-free in xmlEncodeEntitiesInternal - debian/patches/CVE-2021-3516.patch: Call htmlCtxtUseOptions to make sure that names aren't stored in dictionaries. - CVE-2021-3516 * SECURITY UPDATE: heap-based buffer overflow in xmlEncodeEntitiesInternal - debian/patches/CVE-2021-3517.patch: Add some checks to validate input is UTF-8 format, supplementing CVE-2020-24977 fix. - CVE-2021-3517 * SECURITY UPDATE: use-after-free in xmlXIncludeDoProcess - debian/patches/CVE-2021-3518.patch: Move from a block list to an allow list approach to avoid descending into other node types that can't contain elements. - CVE-2021-3518 * SECURITY UPDATE: NULL pointer dereference in xmlValidBuildAContentModel - debian/patches/CVE-2021-3537.patch: Check return value of recursive calls to xmlParseElementChildrenContentDeclPriv and return immediately in case of errors. - CVE-2021-3537 * SECURITY UPDATE: Exponential entity expansion - debian/patches/Patch-for-security-issue-CVE-2021-3541.patch: Add check to xmlParserEntityCheck to prevent entity exponential. - CVE-2021-3541 Checksums-Sha1: 1dc74108cc77ba252f7fd69de74ba0c3fe6a6633 2346452 libxml2-dbgsym_2.9.10+dfsg-6.3ubuntu0.1_s390x.ddeb 20edb525994c99aa13953cbea42b67ce05a49810 761444 libxml2-dev_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb b79c833822bb361b6ffdd89173572ee8cc04a5e8 82332 libxml2-utils-dbgsym_2.9.10+dfsg-6.3ubuntu0.1_s390x.ddeb e92398f35c53902b26a7a408dea4dc06c90fe815 35440 libxml2-utils_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb ea24c3ad7e9a684457f4f20a1caf8e5bf640704d 8982 libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.buildinfo 1258088b39e22fb8e5cb590d65f4ce3ae116d557 615508 libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb 5a616c81c8bbeba988e7340e15730526b33c2875 428920 python3-libxml2-dbg_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb 5a27900923a640330dbffd52e023ff9debb10977 124780 python3-libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb Checksums-Sha256: bb98e5a8ec92c82f25cc717bc68cefdd371ef8586f86dc7db2ca23c84f1a184a 2346452 libxml2-dbgsym_2.9.10+dfsg-6.3ubuntu0.1_s390x.ddeb 155ac5869006faec63b997ac6de9c519490b04af9f595bd9d2d3e26eb0d2f87a 761444 libxml2-dev_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb afce5a9b8bab2fefeb0979ae033902c243448eade5141852a70c90b50e6648d7 82332 libxml2-utils-dbgsym_2.9.10+dfsg-6.3ubuntu0.1_s390x.ddeb f775e14ea8bf15fd52428c818185cd0da743ce6484f6b68488d5a729b898e703 35440 libxml2-utils_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb c47ddd74585efbaabada3287ceeb2d294d3083741224f5211736679b99643ed2 8982 libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.buildinfo ad56fce0ca389020cdf4251e2c63342517604f4da5f824a23d7b5f7fedce3889 615508 libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb f230de28b9b9feefc6985f1962fed44039159f1c7e0a763069b438e42f9ecbd9 428920 python3-libxml2-dbg_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb eef2dc4b38b3cb90b33f8309271b366df049baa64642aeea1e870c79143c2489 124780 python3-libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb Files: e236e85a32dc86393c5796acfc104832 2346452 debug optional libxml2-dbgsym_2.9.10+dfsg-6.3ubuntu0.1_s390x.ddeb 6a29853b393b4e3db7c0889366fe385f 761444 libdevel optional libxml2-dev_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb fb2a82b7bd5c3051e8ec9b7fcead10b7 82332 debug optional libxml2-utils-dbgsym_2.9.10+dfsg-6.3ubuntu0.1_s390x.ddeb 32457272132d81ca865cfda3f4dd2ee5 35440 text optional libxml2-utils_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb e2e9a684cb921b98836e949dc883005a 8982 libs optional libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.buildinfo ac19078066eacdf7adabdbb7998d17ae 615508 libs optional libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb 65f66c1dccc79f041aa365160aff9655 428920 debug optional python3-libxml2-dbg_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb 9b73bc2269fb3e8bb6a7fa1c898b071b 124780 python optional python3-libxml2_2.9.10+dfsg-6.3ubuntu0.1_s390x.deb Original-Maintainer: Debian XML/SGML Group