Your message dated Wed, 08 Jun 2011 01:54:52 +0000
with message-id <e1qu7yu-00088h...@franck.debian.org>
and subject line Bug#628537: fixed in libxml2 2.6.32.dfsg-5+lenny4
has caused the Debian Bug report #628537,
regarding libxml2: overflow issues
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
628537: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628537
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
package: libxml2
version: 2.7.8.dfsg-2
severity: serious
tag: security
some overflow issues were disclosed for libxml2. see:
http://scarybeastsecurity.blogspot.com/2011/05/libxml-vulnerability-and-interesting.html
best wishes,
mike
--- End Message ---
--- Begin Message ---
Source: libxml2
Source-Version: 2.6.32.dfsg-5+lenny4
We believe that the bug you reported is fixed in the latest version of
libxml2, which is due to be installed in the Debian FTP archive:
libxml2-dbg_2.6.32.dfsg-5+lenny4_amd64.deb
to main/libx/libxml2/libxml2-dbg_2.6.32.dfsg-5+lenny4_amd64.deb
libxml2-dev_2.6.32.dfsg-5+lenny4_amd64.deb
to main/libx/libxml2/libxml2-dev_2.6.32.dfsg-5+lenny4_amd64.deb
libxml2-doc_2.6.32.dfsg-5+lenny4_all.deb
to main/libx/libxml2/libxml2-doc_2.6.32.dfsg-5+lenny4_all.deb
libxml2-utils_2.6.32.dfsg-5+lenny4_amd64.deb
to main/libx/libxml2/libxml2-utils_2.6.32.dfsg-5+lenny4_amd64.deb
libxml2_2.6.32.dfsg-5+lenny4.diff.gz
to main/libx/libxml2/libxml2_2.6.32.dfsg-5+lenny4.diff.gz
libxml2_2.6.32.dfsg-5+lenny4.dsc
to main/libx/libxml2/libxml2_2.6.32.dfsg-5+lenny4.dsc
libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
to main/libx/libxml2/libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
python-libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
to main/libx/libxml2/python-libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 628...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Mike Hommey <gland...@debian.org> (supplier of updated libxml2 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sat, 04 Jun 2011 10:41:00 +0900
Source: libxml2
Binary: libxml2 libxml2-utils libxml2-dev libxml2-dbg libxml2-doc python-libxml2
Architecture: source all amd64
Version: 2.6.32.dfsg-5+lenny4
Distribution: oldstable-security
Urgency: low
Maintainer: Debian XML/SGML Group <debian-xml-sgml-p...@lists.alioth.debian.org>
Changed-By: Mike Hommey <gland...@debian.org>
Description:
libxml2 - GNOME XML library
libxml2-dbg - Debugging symbols for the GNOME XML library
libxml2-dev - Development files for the GNOME XML library
libxml2-doc - Documentation for the GNOME XML library
libxml2-utils - XML utilities
python-libxml2 - Python bindings for the GNOME XML library
Closes: 628537
Changes:
libxml2 (2.6.32.dfsg-5+lenny4) oldstable-security; urgency=low
.
* xpath.c: Fix some potential problems on reallocation failures.
Closes: #628537.
Checksums-Sha1:
b606ce1aa535b890381c21dbbe211ede36799c5e 1985 libxml2_2.6.32.dfsg-5+lenny4.dsc
d3497a0f9e5c8b76fa7b73dae9d23537b2644538 84794
libxml2_2.6.32.dfsg-5+lenny4.diff.gz
892c2ae78fe5f47db5a9baab81075221f542a9ad 1307358
libxml2-doc_2.6.32.dfsg-5+lenny4_all.deb
af86b89b63844fd7b1d1775e36dbb745aa520b2e 860968
libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
0d6ab0729c7f2cc724782679d34ed485a7510032 37324
libxml2-utils_2.6.32.dfsg-5+lenny4_amd64.deb
17f038e180ca1fed4a343a15a9b224b81287ecbb 774136
libxml2-dev_2.6.32.dfsg-5+lenny4_amd64.deb
68f5d3ec18a553502db8cc553ca1aec3961e1cca 988376
libxml2-dbg_2.6.32.dfsg-5+lenny4_amd64.deb
18c960cda9ce0e652662e963c8ae7acb711c5b50 295944
python-libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
Checksums-Sha256:
f1f774dff4a8bdc69e3aa3866ad257ee3b8c94aceb615ff5325db0c74ef29580 1985
libxml2_2.6.32.dfsg-5+lenny4.dsc
45816fe7cc01afaf6243f577e403f80027b42dfbaa6815092b100353ae541857 84794
libxml2_2.6.32.dfsg-5+lenny4.diff.gz
4d4bd20031993b26992f239027e30f4e01a2bf3701af6f1b36c5f90647500228 1307358
libxml2-doc_2.6.32.dfsg-5+lenny4_all.deb
ba421bc5a90352ad315cda2888941b1485a1a044cf9c0b5ab7a8188dc800642a 860968
libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
312eb5f4cc332d1f5e31d3eed9efbf69a068c6b93fbd865f793b1a911a148c0b 37324
libxml2-utils_2.6.32.dfsg-5+lenny4_amd64.deb
b649f572a1fe7aa3cb20a3a7ef8cc204ef43499b1d46cac6f41a4734b37fca88 774136
libxml2-dev_2.6.32.dfsg-5+lenny4_amd64.deb
d97033768c54563510fcc1c411222c93a3baaf5712ea74d6487aa5e169d373c6 988376
libxml2-dbg_2.6.32.dfsg-5+lenny4_amd64.deb
e415b3b45aaa299beb95ac28ff209490a41dd9bd2cd939ba8799be0767c5ae51 295944
python-libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
Files:
9a0ac0544938b2009d3e447425587787 1985 libs optional
libxml2_2.6.32.dfsg-5+lenny4.dsc
73b2c2e770ce1a939b2b559450450c35 84794 libs optional
libxml2_2.6.32.dfsg-5+lenny4.diff.gz
48f4bfa6fe8f23826a2d3192cedc6322 1307358 doc optional
libxml2-doc_2.6.32.dfsg-5+lenny4_all.deb
c75a029901edcf0e0b76c52aaf0321ad 860968 libs optional
libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
956bc24398ba5f5a8ac46cfb4e205cf4 37324 text optional
libxml2-utils_2.6.32.dfsg-5+lenny4_amd64.deb
738d601f6eb4160c4165962649392c31 774136 libdevel optional
libxml2-dev_2.6.32.dfsg-5+lenny4_amd64.deb
ba1fa29ea40aaade671a60e9f12bea0b 988376 libdevel extra
libxml2-dbg_2.6.32.dfsg-5+lenny4_amd64.deb
951d141d448eb9e2dd7d93cf9f3e4d34 295944 python optional
python-libxml2_2.6.32.dfsg-5+lenny4_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iQIVAwUBTemPWOQqoE+mqoxyAQgADA/8CS3NZQGJKkCoEEigMWrxcyCu8HTXtZue
WY4T8+/9vFTnt5aqm4q9N5dTwp80igXoNrUOcm5POrGCoftRcyy/heDL9tH3Phvg
28MIFIItQh/Sqs2k9nGXn4sMlh+CHe8/KWa3GyWG4C8fxjl1kEYtmTV8sj3BmrJb
U9nLWSqW7k28Fe8Sz5Kg9T+G6hYJNiJypieTo+cZq+43dTF54qzJnMCDalSgVxR6
WBrDil+iHRW+gqkr9T1SYY9BMfaw4Id0p8+ksDVUX13+0BzPD5uIoW7+iBXzTP2I
sz1K58QXL3g8rH0vBIEzmqbwlvD2F0e2vVJGzouC1T3cC6dkj2Hsxp/QU/yocYP5
tbGXfaxE3DRZu5TcxfPPYCwfqwmwEppZx8zgJJotK/GuJjd/kcP/c6fpU+11vjQ1
VpHVZqNAQ1FPnrJSmeYDTZeAqrmy1S2TZU2MTEljAC3kFzLZ0J/AYZxUsKO4g50X
92hAWjy0HPrne2Zz3iR7sjbOVHM/er3jaACuJjycWs2aMR9JZQyfT4wRJwe5hLz5
c8wR+6wzOYSGsWMi6CR6Jj0o9wRIdf7kc6zb9KMmg0GgfLjdmLmd+MrggKWOPLqW
ojqrBwQMsYKy/nG6C5mkenxLt7mLsJ9Tmb7xh9a21Smg5Wn0XuUL7jmaRAbGWzsq
W6wKxMhHKo0=
=OfBV
-----END PGP SIGNATURE-----
--- End Message ---