-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 18 Jun 2016 19:27:31 +0200 Source: libxslt Binary: libxslt1.1 libxslt1-dev libxslt1-dbg xsltproc python-libxslt1 python-libxslt1-dbg Architecture: amd64 Version: 1.1.28-2+deb8u1 Distribution: jessie-security Urgency: high Maintainer: amd64 Build Daemon (binet) Changed-By: Salvatore Bonaccorso Description: libxslt1-dbg - XSLT 1.0 processing library - debugging symbols libxslt1-dev - XSLT 1.0 processing library - development kit libxslt1.1 - XSLT 1.0 processing library - runtime library python-libxslt1 - Python bindings for libxslt1 python-libxslt1-dbg - Python bindings for libxslt1 (debug extension) xsltproc - XSLT 1.0 command line processor Closes: 802971 Changes: libxslt (1.1.28-2+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix for type confusion in preprocessing attributes (CVE-2015-7995) (Closes: #802971) * Always initialize EXSLT month and day to 1 * Fix use-after-free in xsltDocumentFunctionLoadDocument * Fix xsltNumberFormatGetMultipleLevel (CVE-2016-1683) * Round xsl:number values to nearest integer * Handle negative xsl:number values * Lower bound for format token "a" * Lower and upper bound for format token "i" (CVE-2016-1684) * Fix double free in libexslt hash functions * Fix buffer overflow in exsltDateFormat * Fix OOB heap read in xsltExtModuleRegisterDynamic Checksums-Sha1: ef340cb2de167f51840d2c0c2a0e2a3386b78d2b 232188 libxslt1.1_1.1.28-2+deb8u1_amd64.deb 5e1ff10c260f78e666bc9b8af94d3a3b1c75154e 511092 libxslt1-dev_1.1.28-2+deb8u1_amd64.deb 696aeda45f15ac0bfa1fc41a0ceaeb516b7112b3 479886 libxslt1-dbg_1.1.28-2+deb8u1_amd64.deb ebae32aca9987baafa501eee9c8d4cb65eea6c76 118176 xsltproc_1.1.28-2+deb8u1_amd64.deb 8020e7778e11cf231f4c075971154e9a55493215 138628 python-libxslt1_1.1.28-2+deb8u1_amd64.deb 861d146cdae64bae8b31ab2bc4426486fe445fbd 221508 python-libxslt1-dbg_1.1.28-2+deb8u1_amd64.deb Checksums-Sha256: 8a0f7ef8204dab62bde764a303aecea2a551133b656ba0523000e52c3c7542f7 232188 libxslt1.1_1.1.28-2+deb8u1_amd64.deb ccc7ed037839eefcf11f241759fb8c7032665cb25418d1d276c84ee09e7a00fb 511092 libxslt1-dev_1.1.28-2+deb8u1_amd64.deb 0b98643ddcf6262a3920d6e7361806f88528cfc04e04501a92a0f3b52882681f 479886 libxslt1-dbg_1.1.28-2+deb8u1_amd64.deb d0f844434c203e05b00e4dbb1f76ae4b28f2e4f8eba3c35dd103f1aa7d1ee1b5 118176 xsltproc_1.1.28-2+deb8u1_amd64.deb 952bc6fd58f6c6e2a5468d84187f7d76ef8604704fad8484d967189017fb6343 138628 python-libxslt1_1.1.28-2+deb8u1_amd64.deb be6e23c552d21aefcea7a9a5dfb835fd37d35cd509712a49463bdae49ef3577c 221508 python-libxslt1-dbg_1.1.28-2+deb8u1_amd64.deb Files: f86e504c43ff1282fb9886daa1a44dde 232188 libs optional libxslt1.1_1.1.28-2+deb8u1_amd64.deb b0527222562d11be22e72e1ce9ff0440 511092 libdevel optional libxslt1-dev_1.1.28-2+deb8u1_amd64.deb 2a8118e20cc92bde5c6bfcdeeea4ae99 479886 debug extra libxslt1-dbg_1.1.28-2+deb8u1_amd64.deb ecec9c8a68ce6bcebcf3d187adc5d609 118176 text optional xsltproc_1.1.28-2+deb8u1_amd64.deb bff849a4bcad854df26c6a22aaa174b0 138628 python optional python-libxslt1_1.1.28-2+deb8u1_amd64.deb b0a4d1033aabfd03ef4ca6cf3ff3e99e 221508 debug extra python-libxslt1-dbg_1.1.28-2+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJXZbPZAAoJEEQSPqnl82l3uOkP/3SixItxRVDd2W+pY1bL+S47 pI8IIng8V+lwU3m55eCDAnLgAPXLWADPlqagMIS3W1eSw2DIOJA+vJN4gm6ny9jo 7R1xAjYRc0BBAIVm0rLiSo2rzwAnQhrc+valtF5C+RdUlq7cQBJ3Kwy0KkhwGqNK EUSyccammr8oPSfJbFcdYL8HSYjP5cQoWU0nPNKWZFqXmu9fwwgmxDl9n5YOZHUc 0q606rVOz8nYrczHhSa2F6wZ59t3hKh8v1ib/P+5HVbNOSgY5mfgjdqfm2VIjV3L nA1ha3IE+LZse47tTiSEsaMPzeRVaEDO8gpVKzi4KSIfUjHczSqT2t8ktDbCPqgZ znZ1unuH3Xl2QgRe8dpx2Qt9k8fHi4ejCOB/wJ/k+bXWv9xXVQvu4ZYImPiOGtE6 nn+tRVqZeVgWbV4isCmqwGagHQPWT18EXWn59rTNw5mhLxWvTqCTL3KyR8xq2tBT UZ+Yv/LcsFgPUKvt7rR2o2oWQiVYR1i7TrJs7/051VYctMsolLQCdgO3SsqPWlp/ s7sZeNN2SV5sm8wo4vNDBFJbFibBhkr6KmRwKcik3XX5DvRBv+D88pywCvGAEg9i r+csGvt+0HICzAvijjR1QM/XlQmatmguwOkubNTy0gJ9XcunoWOPj1RtkcCsXQig nGfpwYE5f9HOSiVHWixl =RD0x -----END PGP SIGNATURE-----