Ross Burton
a36c28943d
libxml2: remove patch for CVE-2012-2871
...
This CVE patch is actually against Chromium as they ship an internal fork of
libxml2 and breaks ABI. The real issue has been resolved in libxslt 1.1.27, and
we're shipping 1.1.28.
(From OE-Core rev: e6c60252ab4ba6842f63c6b8a519a85f2ff238fb)
(From OE-Core rev: 82b91d2484a4430a9b6689d0b6b07e6f62392266)
Signed-off-by: Ross Burton <ross.burton@intel.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2013-10-10 12:31:14 +01:00
Li Wang
8780c5ddf2
libxml2 CVE-2012-2871
...
the patch come from:
http://src.chromium.org/viewvc/chrome/trunk/src/third_party/libxml/src \
/include/libxml/tree.h?r1=56276&r2=149930
libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89,
does not properly support a cast of an unspecified variable during handling
of XSL transforms, which allows remote attackers to cause a denial of service
or possibly have unknown other impact via a crafted document, related to the
_xmlNs data structure in include/libxml/tree.h.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2871
[YOCTO #3580 ]
[ CQID: WIND00376779 ]
Upstream-Status: Pending
(From OE-Core rev: bc601f96f34ad17a87f599b58e502ec1b2c13fa3)
Signed-off-by: Li Wang <li.wang@windriver.com >
Signed-off-by: Saul Wold <sgw@linux.intel.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2012-12-17 17:24:56 +00:00
Zhenhua Luo
2fc707a55c
libxml2: update PR to contain INC_PR to reflect the update of inc file
...
(From OE-Core rev: 4c18e34f113bc46b0619fc8576475694224f8b40)
Signed-off-by: Zhenhua Luo <b19537@freescale.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2012-12-04 18:02:00 +00:00
Saul Wold
c6ea431eae
libxml2: Update to 2.9.0
...
(From OE-Core rev: a65ea43e26866ddc60051c52b2eb226507fae346)
Signed-off-by: Saul Wold <sgw@linux.intel.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2012-11-21 16:55:59 +00:00