Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-10 Thread Moritz Muehlenhoff
On Mon, Jun 09, 2014 at 09:01:46PM +1000, Hamish Moffatt wrote: > On 09/06/14 15:17, Salvatore Bonaccorso wrote: >> Hi, >> >> On Sun, Jun 01, 2014 at 11:30:15PM -0300, Lisandro Damián Nicanor Pérez >> Meyer wrote: >>> tag 750141 moreinfo >>> thanks >>> >>> On Monday 02 June 2014 11:19:05 Hamish Mo

Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-09 Thread Hamish Moffatt
On 09/06/14 15:17, Salvatore Bonaccorso wrote: Hi, On Sun, Jun 01, 2014 at 11:30:15PM -0300, Lisandro Damián Nicanor Pérez Meyer wrote: tag 750141 moreinfo thanks On Monday 02 June 2014 11:19:05 Hamish Moffatt wrote: Package: libqt4-xml Severity: serious Tags: security Justification: securit

Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-08 Thread Salvatore Bonaccorso
Hi, On Sun, Jun 01, 2014 at 11:30:15PM -0300, Lisandro Damián Nicanor Pérez Meyer wrote: > tag 750141 moreinfo > thanks > > On Monday 02 June 2014 11:19:05 Hamish Moffatt wrote: > > Package: libqt4-xml > > Severity: serious > > Tags: security > > Justification: security > > > > Qt 4.8.6 has a f

Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-01 Thread Lisandro Damián Nicanor Pérez Meyer
tag 750141 moreinfo thanks On Monday 02 June 2014 11:19:05 Hamish Moffatt wrote: > Package: libqt4-xml > Severity: serious > Tags: security > Justification: security > > Qt 4.8.6 has a fix for a denial of service attack due to XML entity > expansion ("billion laughs attack"). This fix doesn't see

Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-01 Thread Hamish Moffatt
Package: libqt4-xml Severity: serious Tags: security Justification: security Qt 4.8.6 has a fix for a denial of service attack due to XML entity expansion ("billion laughs attack"). This fix doesn't seem to be in the wheezy packages yet. http://blog.qt.digia.com/blog/2014/04/24/qt-4-8-6-released/