From e482a430ec4f8507f5a5caf06b3e72f4c30edfea Mon Sep 17 00:00:00 2001 From: Gustavo Zacarias Date: Tue, 6 Mar 2012 09:10:43 -0300 Subject: expat: add security patch for CVE-2009-3560 Signed-off-by: Gustavo Zacarias Signed-off-by: Peter Korsgaard --- package/expat/expat-2.0.1-CVE-2009-3560.patch | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 package/expat/expat-2.0.1-CVE-2009-3560.patch (limited to 'package/expat') diff --git a/package/expat/expat-2.0.1-CVE-2009-3560.patch b/package/expat/expat-2.0.1-CVE-2009-3560.patch new file mode 100644 index 000000000..7cadc47b0 --- /dev/null +++ b/package/expat/expat-2.0.1-CVE-2009-3560.patch @@ -0,0 +1,14 @@ +http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3560 + +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3703,6 +3703,9 @@ doProlog(XML_Parser parser, + return XML_ERROR_UNCLOSED_TOKEN; + case XML_TOK_PARTIAL_CHAR: + return XML_ERROR_PARTIAL_CHAR; ++ case -XML_TOK_PROLOG_S: ++ tok = -tok; ++ break; + case XML_TOK_NONE: + #ifdef XML_DTD + /* for internal PE NOT referenced between declarations */ -- cgit v1.2.3