Debian-LTS alert DLA-214-1 (libxml-libxml-perl)
| From: | Raphael Hertzog <hertzog@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 214-1] libxml-libxml-perl security update | |
| Date: | Thu, 30 Apr 2015 18:18:55 +0200 | |
| Message-ID: | <20150430161855.GA13657@home.ouaza.com> |
Package : libxml-libxml-perl Version : 1.70.ds-1+deb6u1 CVE ID : CVE-2015-3451 Debian Bug : 783443 In some cases, XML::LibXML did not respect the request to disable entities expansion. Applications handling untrusted XML files can then be tricked into disclosing the content of local files. In Debian 6 “Squeeze”, this issue has been fixed in libxml-libxml-perl version 1.70.ds-1+deb6u1. -- Raphaël Hertzog ◈ Debian Developer Support Debian LTS: http://www.freexian.com/services/debian-lts.html Learn to master Debian: http://debian-handbook.info/get/
