[Bug 755814] CVE-2011-0216 CVE-2011-3905 CVE-2011-3919 mingw32-libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]

bugzilla at redhat.com bugzilla at redhat.com
Tue Jan 17 14:04:40 UTC 2012


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug.


https://bugzilla.redhat.com/show_bug.cgi?id=755814

Paul Howarth <paul at city-fan.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |paul at city-fan.org

--- Comment #1 from Paul Howarth <paul at city-fan.org> 2012-01-17 09:04:40 EST ---
I'm about to attach a series of patches against Rawhide git that pull in
changes from upstream and RHEL 6 to address:

* CVE-2011-0216
* CVE-2011-1944
* CVE-2011-2834
* CVE-2011-3905
* CVE-2011-3919
* XPath hardening fixes from RHEL-6

I could apply these patches as a provenpackager, or I'm willing to become
co-maintainer in Fedora. However, I'd prefer Daniel's feedback first given that
he is both upstream and RHEL maintainer and knows much more than I do.

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.


More information about the mingw mailing list