|
|
Log in / Subscribe / Register

Debian alert DLA-4522-1 (libxml-parser-perl)

From:  Guilhem Moulin <guilhem@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4522-1] libxml-parser-perl security update
Date:  Sat, 04 Apr 2026 09:14:21 +0200
Message-ID:  <adC6Tec0bVr84j-K@debian.org>

------------------------------------------------------------------------- Debian LTS Advisory DLA-4522-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin April 04, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libxml-parser-perl Version : 2.46-2+deb11u1 CVE ID : CVE-2006-10003 Debian Bug : 378412 It was discovered that libxml-parser-perl, a Perl module for parsing XML files, was prone to an off-by-one heap buffer overflow in `st_serial_stack()`. This update also includes a follow-up improvement change for CVE-2006-10002 (buffer overwrite in `parse_stream()`.) For Debian 11 bullseye, these problems have been fixed in version 2.46-2+deb11u1. We recommend that you upgrade your libxml-parser-perl packages. For the detailed security status of libxml-parser-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libxml-parser... Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIyBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmnQuk0ACgkQ05pJnDwh pVKBNw/4vdGob1FwAL8jES9PIuvtxm86e8fioR0PNwSIuOnFtRitEADDmvxE+McK lDk+hRTuU95PyYO+HzNrzJw4jNRaG0RXnWPgjaBV79m0Kwl4rGCxl2XCPHFHMLrT qy8qJy7o/9R6gD0jLNTwF/GtzQQq0LjgkaTYS1xExZz+fbjyEVkhCVILWLM01dR+ 0rmOTISo9Ow4UZikTX1arbkjuVRLvdX7V4bYEeaqhR+x/siyjmBrDnHCES9mBtKK cwb3OF1MQci0dPAqv5A1l9+PP55PdmZykqQwD8i+X21lNjprSkmYGi1hH13I/bSi N4bjiLIz+bqPXCnMYkmygVfWOSsxKFTscJVwbp85+T9AHb6O1aHwlBKhYuWReLPQ ql8ioAzDeq/UqZ2ggVOAKJgvbhTOvKE01SvLEoRh9QSQOi+WOdjKZXIGojH8RyJD JEexRXH6whD7OqWyrRlTKxYIYmhJIS8XAK0hSDL60KLcRO/m8FUXKQeFJKuK1vjs 4D3ymrm4urcfjB5+3FTEnb3LB9WjKw/zjIsUAkW2t8y48BKlTZPpQfpp9bTmF1Xm WHQ9UurJUY46c9FDt6/0bH/wyEfpLV9NNVANkHCkwZjIqdpAYjL2MiO/d2zQNUkk OyYk3E/h2cqO1uFBf2isuWfhbHUQ/I5EwBri0Mz0kMiLTxXDxw== =GsPB -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds