-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 18 Jun 2016 19:27:31 +0200 Source: libxslt Binary: libxslt1.1 libxslt1-dev libxslt1-dbg xsltproc python-libxslt1 python-libxslt1-dbg Architecture: i386 Version: 1.1.28-2+deb8u1 Distribution: jessie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Salvatore Bonaccorso Description: libxslt1-dbg - XSLT 1.0 processing library - debugging symbols libxslt1-dev - XSLT 1.0 processing library - development kit libxslt1.1 - XSLT 1.0 processing library - runtime library python-libxslt1 - Python bindings for libxslt1 python-libxslt1-dbg - Python bindings for libxslt1 (debug extension) xsltproc - XSLT 1.0 command line processor Closes: 802971 Changes: libxslt (1.1.28-2+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix for type confusion in preprocessing attributes (CVE-2015-7995) (Closes: #802971) * Always initialize EXSLT month and day to 1 * Fix use-after-free in xsltDocumentFunctionLoadDocument * Fix xsltNumberFormatGetMultipleLevel (CVE-2016-1683) * Round xsl:number values to nearest integer * Handle negative xsl:number values * Lower bound for format token "a" * Lower and upper bound for format token "i" (CVE-2016-1684) * Fix double free in libexslt hash functions * Fix buffer overflow in exsltDateFormat * Fix OOB heap read in xsltExtModuleRegisterDynamic Checksums-Sha1: f4eaca458172ac15a5c197daa2cb4068c47d95e7 240640 libxslt1.1_1.1.28-2+deb8u1_i386.deb 46f81770494df7e50101ecd3a2cef71570cd2c69 524388 libxslt1-dev_1.1.28-2+deb8u1_i386.deb 218504afc19d8cda841a96b1e18cfd30e5ba39f1 383948 libxslt1-dbg_1.1.28-2+deb8u1_i386.deb f0621a16bd3924d5b26a2d41e6a176ff94c80a4c 118312 xsltproc_1.1.28-2+deb8u1_i386.deb c95318cee79267f33693935fa4fea182b6d5c23a 139054 python-libxslt1_1.1.28-2+deb8u1_i386.deb 4349080f92516b3e75882be4bb59b36f1ed51049 210266 python-libxslt1-dbg_1.1.28-2+deb8u1_i386.deb Checksums-Sha256: f7abba192fb731034b800166c9727b2acfa2006725ba01ebe1fd74b86f2798e0 240640 libxslt1.1_1.1.28-2+deb8u1_i386.deb 2837a2ae987ef2c976637c96cbcdf868c369c573ba18b77bfc93b302b6e9c0e0 524388 libxslt1-dev_1.1.28-2+deb8u1_i386.deb 9bc813dedfff3df47821aa3654f661b06926503ba0cb28f207120285277e6b4b 383948 libxslt1-dbg_1.1.28-2+deb8u1_i386.deb a309139f488e6bb207bfe4cac05fcf169c67232f030b17fc824c3d794c4bad1d 118312 xsltproc_1.1.28-2+deb8u1_i386.deb ed0054fbc2789868680a6310ee629e885d2da1ffe14394629d2b7edae83549b2 139054 python-libxslt1_1.1.28-2+deb8u1_i386.deb e253fb1aa298c7acb6f5c7f828d5da23033ff3ab66109d62f8ab6885c96c6828 210266 python-libxslt1-dbg_1.1.28-2+deb8u1_i386.deb Files: a0b305bc27faf914ebeff41ee4eab0f2 240640 libs optional libxslt1.1_1.1.28-2+deb8u1_i386.deb 79d060312c3b7bd126ae5d728c121553 524388 libdevel optional libxslt1-dev_1.1.28-2+deb8u1_i386.deb c0e8d360e1be1478e12c1abb34fc6f15 383948 debug extra libxslt1-dbg_1.1.28-2+deb8u1_i386.deb f5bed940f76988e66ab5666c40260832 118312 text optional xsltproc_1.1.28-2+deb8u1_i386.deb 708a2db612bf509fe75ced548697dfd5 139054 python optional python-libxslt1_1.1.28-2+deb8u1_i386.deb 50509a22d16337c98a69b2092af80de6 210266 debug extra python-libxslt1-dbg_1.1.28-2+deb8u1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJXZbP2AAoJEIk4rQGIRk2LusAQAJhY/aZ0MPJhpjX06uWOQNhb Bvww9s3nwA6RLvxTockctrxxkyxThxCRPjNiT64bxyRDC9j7uiwbhRkP2jGVQ9Wk OtX0wGN0p9vhjByqNoQ2LEYTwL2IfTEAQVpKdl4OKbhkekTNzSwT7wr4nZwtLtYP kVyKEUCw1p830e/UukjidDbspxb+6vZNAmOtDdY2bBJyqvl16c0lbeDpCyLyZLHN oHSRwq+ghiUALPVuHh0bo6YNynvMQl+GCUIE+8Ln3cek/5wBBcopJzyI7c8/OSa3 gV4oLkswTpNmeb9kaL3AsBUOQl1iFQlIXydW/6jHw+/pMH3B6u/NRcXzrwDPMkiG yDx12xfRWzvAttGbGHvJpsKWNTOw6N29XTNJ5Xn1PoILnQfjql8vWaexp9My72bW ppbSVTD5n/52ILoHqoVoWUDRe3fAE5JFPQfgMb4/1XcZAMI62UYrYYVKveU7b1Z0 8GB0rOfwsDLleqIAv/NK4VrdrYNBOAejmKPfCk9Jf6HQbc8FZC4nskBoFzpRA2yl DZO2rGi0ku5KjUvHD3+gNQ6pimO8cz4qWLs6UhFkFy7ntERQ2PLCOqrOQSNSj31n z+qrXu+LTBVICNB6r2WrciKE25Y04EXePCOrF5F/yyUIllYKz4rQNKXf+ObkwA6W vfygzIEi/ww15w76u2cw =DwgE -----END PGP SIGNATURE-----