[Bug 1191425] CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [epel-7]

bugzilla at redhat.com bugzilla at redhat.com
Wed Feb 11 11:57:39 UTC 2015


https://bugzilla.redhat.com/show_bug.cgi?id=1191425

Tomas Hoger <thoger at redhat.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |CLOSED
                 CC|                            |drizt at land.ru,
                   |                            |ktietz at redhat.com
          Component|mingw32-libxml2             |mingw-libxml2
         Resolution|---                         |ERRATA
            Summary|CVE-2014-0191               |CVE-2014-0191
                   |mingw32-libxml2: libxml2:   |mingw-libxml2: libxml2:
                   |external parameter entity   |external parameter entity
                   |loaded when entity          |loaded when entity
                   |substitution is disabled    |substitution is disabled
                   |[epel-7]                    |[epel-7]
              Flags|needinfo?(thoger at redhat.com |
                   |)                           |
        Last Closed|                            |2015-02-11 06:57:39



--- Comment #3 from Tomas Hoger <thoger at redhat.com> ---
Sorry, you are correct.  I was updating information about affected packages in
bug 1090976, and I re-used entry for now removed epel-5 mingw32-libxml2 and
failed to change component name while changing epel-5 -> epel-7.  I was also
looking at outdated manifest, which listed 2.9.1 used in epel-7.

https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-4892

-- 
You are receiving this mail because:
You are on the CC list for the bug.
Unsubscribe from this bug https://bugzilla.redhat.com/token.cgi?t=hc1g3mjRJ3&a=cc_unsubscribe


More information about the mingw mailing list