Summary: | [FR] обновить до 1.1.29 | ||
---|---|---|---|
Product: | Sisyphus | Reporter: | Michael Shigorin <mike> |
Component: | libxslt | Assignee: | Dmitry V. Levin <ldv> |
Status: | CLOSED FIXED | QA Contact: | qa-sisyphus |
Severity: | enhancement | ||
Priority: | P3 | CC: | arseny, at, glebfm, ldv, vseleznv |
Version: | unstable | ||
Hardware: | all | ||
OS: | Linux | ||
URL: | https://bugzilla.gnome.org/show_bug.cgi?id=758148 | ||
Bug Depends on: | |||
Bug Blocks: | 34214, 34105 |
Description
Michael Shigorin
2016-11-28 15:23:56 MSK
libxslt-1.1.32-alt1 -> sisyphus: Wed Nov 15 2017 Vladimir D. Seleznev <vseleznv@altlinux> 1.1.32-alt1 - Updated to 1.1.32. - Upstream support for SOURCE_DATE_EPOCH (ALT#32814). - Fixes: + CVE-2017-5029 generation of text nodes integer overflow, + CVE-2016-1684 integer overflow (mishandle the i format token for xsl:number), + CVE-2016-1683 out-of-bounds heap memory access (mishandle namespace nodes). |