[SCM] Debian packaging for XML-Security-C branch, master, updated. debian/1.7.1-1-5-g071f1b6

Russ Allbery rra at debian.org
Thu Jun 27 20:53:27 UTC 2013


The following commit has been merged in the master branch:
commit 1e15db8da40083a1792d6748c4a09d4ba9bd5e49
Author: Russ Allbery <rra at debian.org>
Date:   Thu Jun 27 12:51:48 2013 -0700

    Add changelog for upstream 1.7.2 release

diff --git a/debian/changelog b/debian/changelog
index 096fab3..28b6c41 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,14 @@
+xml-security-c (1.7.2-1) UNRELEASED; urgency=high
+
+  * New upstream release.
+    - The attempted fix to address CVE-2013-2154 introduced the
+      possibility of a heap overflow, possibly leading to arbitrary code
+      execution, in the processing of malformed XPointer expressions in
+      the XML Signature Reference processing code.  Fix that heap
+      overflow.  (CVE-2013-2210)
+
+ -- Russ Allbery <rra at debian.org>  Thu, 27 Jun 2013 12:52:06 -0700
+
 xml-security-c (1.7.1-1) experimental; urgency=high
 
   * New upstream release.

-- 
Debian packaging for XML-Security-C



More information about the Pkg-shibboleth-devel mailing list