Package: libexpat1
Version: 2.2.10-2+deb11u2
Severity: important
X-Debbugs-Cc: t...@security.debian.org

Dear Maintainer,

after several hours of debugging our SOGo installation, we found out
that libwbxml in general was not able to parse any previously parseable
XML documents.

Expected result:

$ xml2wbxml sample_xml_minimal.xml
xml2wbxml succeded

Result after latest security upgrade:

$ xml2wbxml sample_xml_minimal.xml
xml2wbxml failed: Parsing of XML Document Failed

Minimal XML file:

<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE ActiveSync PUBLIC "-//MICROSOFT//DTD ActiveSync//EN" 
"http://www.microsoft.com/";>
<FolderSync xmlns="FolderHierarchy:">
    <Status>1</Status>
</FolderSync>

This happened on Debian 10 and Debian 11 with the Debian supplied
version of libwbxml. 

HTH,

Hanno

-- System Information:
Debian Release: 11.2
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-11-amd64 (SMP w/6 CPU threads)
Kernel taint flags: TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libexpat1 depends on:
ii  libc6  2.31-13+deb11u2

libexpat1 recommends no packages.

libexpat1 suggests no packages.

-- no debconf information

Reply via email to