Files
poky/meta/recipes-core
Joe MacDonald b05755c6ef libxml2: fix CVE-2014-3660
It was discovered that the patch for CVE-2014-0191 for libxml2 is
incomplete.  It is still possible to have libxml2 incorrectly perform
entity substituton even when the application using libxml2 explicitly
disables the feature.  This can allow a remote denial-of-service attack on
systems with libxml2 prior to 2.9.2.

References:
    http://www.openwall.com/lists/oss-security/2014/10/17/7
    https://www.ncsc.nl/actueel/nieuwsberichten/kwetsbaarheid-ontdekt-in-libxml2.html

(From OE-Core rev: 643597a5c432b2e02033d0cefa3ba4da980d078f)

Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2014-10-24 17:36:16 +01:00
..
2014-06-24 19:54:11 +01:00
2014-09-10 11:33:25 +01:00
2014-03-05 17:36:37 +00:00
2014-07-17 12:28:51 +01:00
2014-10-24 17:36:16 +01:00
2014-01-10 15:16:48 +00:00
2014-08-27 12:12:32 +01:00
2014-09-22 13:04:21 +01:00