commit 4784bdbb2422a5746736ee24f21ff881efc6fe9d
Author: Russ Allbery <rra at debian.org>
Date:   Thu Aug 27 11:26:06 2009 -0700

    Better explanation of the upstream security fix

diff --git a/debian/changelog b/debian/changelog
index e9eb5c3..e2404c1 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -2,7 +2,8 @@ xmltooling (1.2.2-1) UNRELEASED; urgency=low
   * New upstream release.
     - SECURITY: Fix potential buffer overflows and reuses of freed objects
-      in error handling code paths with invalid XML.  See
+      in error handling code paths with invalid XML or with malformed
+      URLs.  See the upstream security advisory at
     - Fix other validation issues with malformed objects.
     - Fix for accessing the resolution context, which affects the ability

