Debian alert DLA-4522-1 (libxml-parser-perl)
| From: | Guilhem Moulin <guilhem@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4522-1] libxml-parser-perl security update | |
| Date: | Sat, 04 Apr 2026 09:14:21 +0200 | |
| Message-ID: | <adC6Tec0bVr84j-K@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4522-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin April 04, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libxml-parser-perl Version : 2.46-2+deb11u1 CVE ID : CVE-2006-10003 Debian Bug : 378412 It was discovered that libxml-parser-perl, a Perl module for parsing XML files, was prone to an off-by-one heap buffer overflow in `st_serial_stack()`. This update also includes a follow-up improvement change for CVE-2006-10002 (buffer overwrite in `parse_stream()`.) For Debian 11 bullseye, these problems have been fixed in version 2.46-2+deb11u1. We recommend that you upgrade your libxml-parser-perl packages. For the detailed security status of libxml-parser-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libxml-parser... Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIyBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmnQuk0ACgkQ05pJnDwh pVKBNw/4vdGob1FwAL8jES9PIuvtxm86e8fioR0PNwSIuOnFtRitEADDmvxE+McK lDk+hRTuU95PyYO+HzNrzJw4jNRaG0RXnWPgjaBV79m0Kwl4rGCxl2XCPHFHMLrT qy8qJy7o/9R6gD0jLNTwF/GtzQQq0LjgkaTYS1xExZz+fbjyEVkhCVILWLM01dR+ 0rmOTISo9Ow4UZikTX1arbkjuVRLvdX7V4bYEeaqhR+x/siyjmBrDnHCES9mBtKK cwb3OF1MQci0dPAqv5A1l9+PP55PdmZykqQwD8i+X21lNjprSkmYGi1hH13I/bSi N4bjiLIz+bqPXCnMYkmygVfWOSsxKFTscJVwbp85+T9AHb6O1aHwlBKhYuWReLPQ ql8ioAzDeq/UqZ2ggVOAKJgvbhTOvKE01SvLEoRh9QSQOi+WOdjKZXIGojH8RyJD JEexRXH6whD7OqWyrRlTKxYIYmhJIS8XAK0hSDL60KLcRO/m8FUXKQeFJKuK1vjs 4D3ymrm4urcfjB5+3FTEnb3LB9WjKw/zjIsUAkW2t8y48BKlTZPpQfpp9bTmF1Xm WHQ9UurJUY46c9FDt6/0bH/wyEfpLV9NNVANkHCkwZjIqdpAYjL2MiO/d2zQNUkk OyYk3E/h2cqO1uFBf2isuWfhbHUQ/I5EwBri0Mz0kMiLTxXDxw== =GsPB -----END PGP SIGNATURE-----
