• [SECURITY] [DSA 2137-1] Security update for libxml2

    From Moritz Muehlenhoff@1:229/2 to All on Sun Dec 26 16:50:02 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2137-1 [email protected] http://www.debian.org/security/ Moritz Muehlenhoff December 26, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : libxml2
    Vulnerability : several
    Problem type : local(remote)
    Debian-specific: no
    CVE Id(s) : CVE-2010-4494

    Yang Dingning discovered a double free in libxml's Xpath processing,
    which might allow the execution of arbitrary code.


    For the stable distribution (lenny), this problem has been fixed
    in version 2.6.32.dfsg-5+lenny3.

    For the upcoming stable distribution (squeeze) and the unstable
    distribution (sid), this problem has been fixed in version
    2.7.8.dfsg-2.

    We recommend that you upgrade your libxml2 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iEYEARECAAYFAk0XYvAACgkQXm3vHE4uyloCnQCghdYhczRUmuYXO8jjz/hWd6mk vBIAmwbh5Ri+mtQB7TrqyGs+oZTBw3gL
    =YRUn
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)