From 0ac95190858e2e8917eb663a543d3cb0cc8e76cb Mon Sep 17 00:00:00 2001 From: aydemir Date: Sat, 12 Nov 2016 09:33:33 +0200 Subject: [PATCH] expat version bump --- ...expat-2.2.0-CVE-2016-0718-regression.patch | 27 +++++++++++++++++++ system/base/expat/pspec.xml | 12 +++++++-- 2 files changed, 37 insertions(+), 2 deletions(-) create mode 100644 system/base/expat/files/expat-2.2.0-CVE-2016-0718-regression.patch diff --git a/system/base/expat/files/expat-2.2.0-CVE-2016-0718-regression.patch b/system/base/expat/files/expat-2.2.0-CVE-2016-0718-regression.patch new file mode 100644 index 00000000..03ea42de --- /dev/null +++ b/system/base/expat/files/expat-2.2.0-CVE-2016-0718-regression.patch @@ -0,0 +1,27 @@ +From 3e6190e433479e56f8c1e5adc1198b3c86b15577 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sun, 17 Jul 2016 20:22:29 +0200 +Subject: [PATCH] Fix regression introduced by patch to CVE-2016-0718 (bug + #539) + +Tag names were cut off in some cases; reported by Andy Wang +--- + expat/lib/xmlparse.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 13e080d..2630310 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -2430,7 +2430,7 @@ doContent(XML_Parser parser, + &fromPtr, rawNameEnd, + (ICHAR **)&toPtr, (ICHAR *)tag->bufEnd - 1); + convLen = (int)(toPtr - (XML_Char *)tag->buf); +- if ((convert_res == XML_CONVERT_COMPLETED) || (convert_res == XML_CONVERT_INPUT_INCOMPLETE)) { ++ if ((fromPtr >= rawNameEnd) || (convert_res == XML_CONVERT_INPUT_INCOMPLETE)) { + tag->name.strLen = convLen; + break; + } +-- +2.9.2 + diff --git a/system/base/expat/pspec.xml b/system/base/expat/pspec.xml index 58290380..79a93a22 100644 --- a/system/base/expat/pspec.xml +++ b/system/base/expat/pspec.xml @@ -12,12 +12,13 @@ library XML parsing libraries This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. - mirrors://sourceforge/expat/expat-2.1.0.tar.gz + mirrors://sourceforge/expat/expat-2.2.0.tar.bz2 gnuconfig glibc-devel + expat-2.2.0-CVE-2016-0718-regression.patch @@ -63,6 +64,13 @@ + + 2016-11-12 + 2.2.0 + Version bump. + Yusuf Aydemir + yusuf.aydemir@pisilnux.org + 2016-04-27 2.1.0 @@ -78,4 +86,4 @@ ertugrulerata@gmail.com - + \ No newline at end of file