-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 18 Jun 2016 19:27:31 +0200 Source: libxslt Binary: libxslt1.1 libxslt1-dev libxslt1-dbg xsltproc python-libxslt1 python-libxslt1-dbg Architecture: armel Version: 1.1.28-2+deb8u1 Distribution: jessie-security Urgency: high Maintainer: armel Build Daemon (arnold) Changed-By: Salvatore Bonaccorso Description: libxslt1-dbg - XSLT 1.0 processing library - debugging symbols libxslt1-dev - XSLT 1.0 processing library - development kit libxslt1.1 - XSLT 1.0 processing library - runtime library python-libxslt1 - Python bindings for libxslt1 python-libxslt1-dbg - Python bindings for libxslt1 (debug extension) xsltproc - XSLT 1.0 command line processor Closes: 802971 Changes: libxslt (1.1.28-2+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix for type confusion in preprocessing attributes (CVE-2015-7995) (Closes: #802971) * Always initialize EXSLT month and day to 1 * Fix use-after-free in xsltDocumentFunctionLoadDocument * Fix xsltNumberFormatGetMultipleLevel (CVE-2016-1683) * Round xsl:number values to nearest integer * Handle negative xsl:number values * Lower bound for format token "a" * Lower and upper bound for format token "i" (CVE-2016-1684) * Fix double free in libexslt hash functions * Fix buffer overflow in exsltDateFormat * Fix OOB heap read in xsltExtModuleRegisterDynamic Checksums-Sha1: e8995689c1f1548f5b7a914cf5115b5e24c4503a 215648 libxslt1.1_1.1.28-2+deb8u1_armel.deb c2636f9ad0f4a5f5500a50b9b2aa7eb91010d051 501528 libxslt1-dev_1.1.28-2+deb8u1_armel.deb aa3b6dca57a3e76ab5e7b1b92c90f6a2e9998580 479958 libxslt1-dbg_1.1.28-2+deb8u1_armel.deb 9c39e9a03879b8dac0b228a70b4c1aee7c8510f8 117850 xsltproc_1.1.28-2+deb8u1_armel.deb ff7a620158455bf348f3b65b7fb071c24de4a4ee 135076 python-libxslt1_1.1.28-2+deb8u1_armel.deb a74aaf463b506f8abdaf52b48633aca0b1a8bb76 220336 python-libxslt1-dbg_1.1.28-2+deb8u1_armel.deb Checksums-Sha256: 566166122c4adee960a9dd9263723422dd1bd04261b4b9666dbffd0f2f5b2e69 215648 libxslt1.1_1.1.28-2+deb8u1_armel.deb 40424ecff99cef9462f16652d1e9f6d5696a46c0a8060c9ec50435c99333209a 501528 libxslt1-dev_1.1.28-2+deb8u1_armel.deb e34d02919c5f57144537579a48a0e78751b8c5746ca468ce7a4189e28bd4c426 479958 libxslt1-dbg_1.1.28-2+deb8u1_armel.deb 837fef154d1525286c9a033e4f888055b910d6928a4526495e154c30747c7364 117850 xsltproc_1.1.28-2+deb8u1_armel.deb 237fbbba471b869f8557583cbd3bdd79081b7c1894a565b8dd190d2af2ab2b37 135076 python-libxslt1_1.1.28-2+deb8u1_armel.deb 950652e5853a37dd008b7fba834eececd843e5f7b7649e371c2e1636bd3dfebc 220336 python-libxslt1-dbg_1.1.28-2+deb8u1_armel.deb Files: f92bc48b71981bd8e370c4ce04bffbaa 215648 libs optional libxslt1.1_1.1.28-2+deb8u1_armel.deb 5389e2d1d99cf2c78263189132e86185 501528 libdevel optional libxslt1-dev_1.1.28-2+deb8u1_armel.deb d1fb118c7ead2698ba100a4b151a1bec 479958 debug extra libxslt1-dbg_1.1.28-2+deb8u1_armel.deb cb8da8575d9e9b7878bfe02fc04121ea 117850 text optional xsltproc_1.1.28-2+deb8u1_armel.deb 22bbffd4f8e1dd5e05efd4719f28f4d3 135076 python optional python-libxslt1_1.1.28-2+deb8u1_armel.deb 770b8670ccb95207f02ab08ba4b2c9ac 220336 debug extra python-libxslt1-dbg_1.1.28-2+deb8u1_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJXZbSUAAoJEIfC+IW704fvQ3kP/3ul05MmKcwAGdipbH1fee72 lpfxmrBYAbrLNR7hun+vC6YyFHQDAP7pn4E4ooiQhWc6z4QhA0p3MvjKGHSyOevw gTErnfOhozA3a3tM0nxIz2YwDR5RhvyGmXINZ34Eu/C/k/f+MhCGWtjcwxtEUprB YiikA9Ew0zLGIpQ4Jo5XUAggb5XknzXi0Il2jCWbAurk86aPz7C4zNPczzJgnvzY f764z8rNFa4oirG9GjZN332bQv1lWADtm57WGyCpgsSrl6GwGMD5WwMKOX+EUPaq WzJ9hEzmkc/thNRglCov70TmNl8hlvlA5/OWaVcZLNaUzMRLEdANHYClFWuKPtnG l//fYYfksWAzmMKhk5xBbo/JHgf80FP39EGwZG1Kjpi1XCe+8Gj/fhr4qvMb2Ouj /XGstfXR+05+ML4x4OL55qwWkr0H2PX+GWE2bC0zaxTQuPGcxOhXgigE1Rd1pW3x yBtkScHgVB7x4rU+1MWFAgH481MahwMbcgMiGrUkGAUmvOc6/A8LERFHBi9dPklv AiNUKO0angQiPs0jIvY8vQRbUcNbYCRvMKxO8wNuOzXQ5gvyOrHJ7Jydih2vEBDN qGzmbBa921dQGphh29uB6LV56mhODfBDYLVPXU9BvbPu7T7vhfKN54iA853qL4qz axYV9IXtyTYeZ59h6Tam =Jyj/ -----END PGP SIGNATURE-----