Bug#714241: xml-security-c: CVE-2013-2210

Russ Allbery rra at debian.org
Thu Jun 27 22:29:42 UTC 2013


Salvatore Bonaccorso <carnil at debian.org> writes:

> Could you double check this, and prepare packages for squeeze and
> wheezy too?

I've uploaded fixed versions for experimental and unstable.  Here are the
debdiff patches for wheezy and squeeze.  Permission to upload to the
security queue?

Please note that Shibboleth doesn't exercise this part of the code, so I
don't personally have any application that tests this part of the
library.  However, the upstream change is fairly simple.

-- 
Russ Allbery (rra at debian.org)               <http://www.eyrie.org/~eagle/>

-------------- next part --------------
A non-text attachment was scrubbed...
Name: squeeze.diff
Type: text/x-diff
Size: 1385 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-shibboleth-devel/attachments/20130627/d0c67b3f/attachment.diff>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: wheezy.diff
Type: text/x-diff
Size: 3538 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-shibboleth-devel/attachments/20130627/d0c67b3f/attachment-0001.diff>


More information about the Pkg-shibboleth-devel mailing list