[SECURITY] Fedora 20 Update: perl-XML-LibXML-2.0119-1.fc20

updates at fedoraproject.org updates at fedoraproject.org
Mon May 11 00:11:21 UTC 2015


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2015-7258
2015-04-30 05:52:51
--------------------------------------------------------------------------------

Name        : perl-XML-LibXML
Product     : Fedora 20
Version     : 2.0119
Release     : 1.fc20
URL         : http://search.cpan.org/dist/XML-LibXML/
Summary     : Perl interface to the libxml2 library
Description :
This module implements a Perl interface to the GNOME libxml2 library
which provides interfaces for parsing and manipulating XML files. This
module allows Perl programmers to make use of the highly capable
validating XML parser and the high performance DOM implementation.

--------------------------------------------------------------------------------
Update Information:

Security fix for
--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr 29 2015 Jitka Plesnikova <jplesnik at redhat.com> - 1:2.0119-1
- 2.0119 bump
- Fixed security bz#1216114
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1216112 - CVE-2015-3451 perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances
        https://bugzilla.redhat.com/show_bug.cgi?id=1216112
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update perl-XML-LibXML' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list