path: root/meta/recipes-core/libxml/libxml2/libxml2-CVE-2014-0191-fix.patch
* libxml2: upgrade to 2.9.3Ross Burton2015-12-011-37/+0
| | | | | | | | | | - Drop all the upstreamed patches - Rework the ansidecl removal so it's contained in a single patch (From OE-Core rev: 88e68f25e1756988692108d4c15dfa8efc94e5e5) Signed-off-by: Ross Burton <> Signed-off-by: Richard Purdie <>
* libxml2: fix CVE-2014-0191Maxin B. John2014-05-081-0/+37
It was discovered that libxml2, a library providing support to read, modify and write XML files, incorrectly performs entity substituton in the doctype prolog, even if the application using libxml2 disabled any entity substitution. A remote attacker could provide a specially-crafted XML file that, when processed, would lead to the exhaustion of CPU and memory resources or file descriptors. Reference: (From OE-Core rev: 674bd59d5e357a4aba18c472ac21712a660a84af) Signed-off-by: Maxin B. John <> Signed-off-by: Saul Wold <> Signed-off-by: Richard Purdie <>