diff --git a/system/base/expat/files/expat-2.2.0-CVE-2016-0718-regression.patch b/system/base/expat/files/expat-2.2.0-CVE-2016-0718-regression.patch new file mode 100644 index 00000000..03ea42de --- /dev/null +++ b/system/base/expat/files/expat-2.2.0-CVE-2016-0718-regression.patch @@ -0,0 +1,27 @@ +From 3e6190e433479e56f8c1e5adc1198b3c86b15577 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sun, 17 Jul 2016 20:22:29 +0200 +Subject: [PATCH] Fix regression introduced by patch to CVE-2016-0718 (bug + #539) + +Tag names were cut off in some cases; reported by Andy Wang +--- + expat/lib/xmlparse.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 13e080d..2630310 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -2430,7 +2430,7 @@ doContent(XML_Parser parser, + &fromPtr, rawNameEnd, + (ICHAR **)&toPtr, (ICHAR *)tag->bufEnd - 1); + convLen = (int)(toPtr - (XML_Char *)tag->buf); +- if ((convert_res == XML_CONVERT_COMPLETED) || (convert_res == XML_CONVERT_INPUT_INCOMPLETE)) { ++ if ((fromPtr >= rawNameEnd) || (convert_res == XML_CONVERT_INPUT_INCOMPLETE)) { + tag->name.strLen = convLen; + break; + } +-- +2.9.2 + diff --git a/system/base/expat/pspec.xml b/system/base/expat/pspec.xml index 58290380..79a93a22 100644 --- a/system/base/expat/pspec.xml +++ b/system/base/expat/pspec.xml @@ -12,12 +12,13 @@ library XML parsing libraries This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. - mirrors://sourceforge/expat/expat-2.1.0.tar.gz + mirrors://sourceforge/expat/expat-2.2.0.tar.bz2 gnuconfig glibc-devel + expat-2.2.0-CVE-2016-0718-regression.patch @@ -63,6 +64,13 @@ + + 2016-11-12 + 2.2.0 + Version bump. + Yusuf Aydemir + yusuf.aydemir@pisilnux.org + 2016-04-27 2.1.0 @@ -78,4 +86,4 @@ ertugrulerata@gmail.com - + \ No newline at end of file