Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
openSUSE
expat.11793
expat.changes
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File expat.changes of Package expat.11793
------------------------------------------------------------------- Tue Jul 2 10:19:02 UTC 2019 - Pedro Monreal Gonzalez <pmonrealgonzalez@suse.com> - Security fix (CVE-2018-20843, bsc#1139937) * Large number of colons in input makes parser consume high amount of resources * Added expat-CVE-2018-20843.patch ------------------------------------------------------------------- Thu Nov 16 10:22:18 UTC 2017 - jengelh@inai.de - Expand description of expat-devel. ------------------------------------------------------------------- Thu Nov 16 09:04:25 UTC 2017 - mpluskal@suse.com - Do not generate manpages from docbook - Temporarily disable profiling due to bug in build system ------------------------------------------------------------------- Wed Nov 8 20:01:31 UTC 2017 - aavindraa@gmail.com - Version update to 2.2.5 Tue October 31 2017 * Bug fixes: - If the parser runs out of memory, make sure its internal state reflects the memory it actually has, not the memory it wanted to have. - The default handler wasn't being called when it should for a SYSTEM or PUBLIC doctype if an entity declaration handler was registered. - Fix a case of mistakenly reported parsing success where XML_StopParser was called from an element handler - Function XML_ErrorString was returning NULL rather than a message for code XML_ERROR_INVALID_ARGUMENT introduced with release 2.2.1 * Other changes: - Add argument -N adding notation declarations - various compiler-specific fixes - Improve docbook2x-man detection - drop expat-docbook.patch * fixed in 0f5186c7b8e503c669e332d944712de010b265f3 - switch to github for release tarballs and website ------------------------------------------------------------------- Thu Oct 26 09:53:50 UTC 2017 - pmonrealgonzalez@suse.com - Version update to 2.2.4 Sat August 19 2017 * Bug fixes: #115 Fix copying of partial characters for UTF-8 input * Other changes: #109 Fix "make check" for non-x86 architectures that default to unsigned type char (-128..127 rather than 0..255) #109 coverage.sh: Cover -funsigned-char Autotools: Introduce --without-xmlwf argument #65 Autotools: Replace handwritten Makefile with GNU Automake #43 CMake: Auto-detect high quality entropy extractors, add new option USE_libbsd=ON to use arc4random_buf of libbsd #74 CMake: Add -fno-strict-aliasing only where supported #114 CMake: Always honor manually set BUILD_* options #114 CMake: Compile man page if docbook2x-man is available, only #117 Include file tests/xmltest.log.expected in source tarball (required for "make run-xmltest") #111 Fix some typos in documentation Version info bumped from 7:5:6 to 7:6:6 - Release 2.2.3 Wed August 2 2017 * Bug fixes: #85 Fix a dangling pointer issue related to realloc * Other changes: #91 Linux: Allow getrandom to fail if nonblocking pool has not yet been initialized and read /dev/urandom then, instead. This is in line with what recent Python does. #86 Check that a UTF-16 encoding in an XML declaration has the right endianness #4 #5 #7 Recover correctly when some reallocations fail Repair "./configure && make" for systems without any provider of high quality entropy and try reading /dev/urandom on those Ensure that user-defined character encodings have converter functions when they are needed Fix mis-leading description of argument -c in xmlwf.1 Rely on macro HAVE_ARC4RANDOM_BUF (rather than __CloudABI__) for CloudABI #100 Fix use of SIPHASH_MAIN in siphash.h #23 Test suite: Fix memory leaks Version info bumped from 7:4:6 to 7:5:6 - Release 2.2.2 Wed July 12 2017 * Security fixes: #43 Protect against compilation without any source of high quality entropy enabled, e.g. with CMake build system; * [MOX-006] Fix non-NULL parser parameter validation in XML_Parse; resulted in NULL dereference, previously; * Bug fixes: #69 Fix improper use of unsigned long long integer literals * Other changes: #73 Start requiring a C99 compiler #49 Fix "==" Bashism in configure script #58 Address compile warnings #68 Fix "./buildconf.sh && ./configure" for some versions of Dash for /bin/sh #72 CMake: Ease use of Expat in context of a parent project with multiple CMakeLists.txt files #72 CMake: Resolve mistaken executable permissions #76 Address compile warning with -DNDEBUG (not recommended!) #77 Address compile warning about macro redefinition * Added patch expat-docbook.patch to compile the man pages with docbook-to-man * Cleaned spec file with spec-cleaner ------------------------------------------------------------------- Sat Oct 7 14:32:27 UTC 2017 - jayvdb@gmail.com - Allow building when do_profiling is undefined ------------------------------------------------------------------- Tue Jul 11 15:02:55 UTC 2017 - mpluskal@suse.com - Build with profiling when possible ------------------------------------------------------------------- Tue Jul 4 14:33:00 UTC 2017 - meissner@suse.com - Version update to 2.2.1 Sat June 17 2017 - Security fixes: CVE-2017-9233 / bsc#1047236 -- External entity infinite loop DoS Details: https://libexpat.github.io/doc/cve-2017-9233/ Commit c4bf96bb51dd2a1b0e185374362ee136fe2c9d7f - [MOX-002] CVE-2016-9063 / bsc#1047240 -- Detect integer overflow; (Fixed version of existing downstream patches!) - (SF.net) #539 Fix regression from fix to CVE-2016-0718 cutting off longer tag names; #25 More integer overflow detection (function poolGrow); - [MOX-002] Detect overflow from len=INT_MAX call to XML_Parse; - [MOX-005] #30 Use high quality entropy for hash initialization: * arc4random_buf on BSD, systems with libbsd (when configured with --with-libbsd), CloudABI * RtlGenRandom on Windows XP / Server 2003 and later * getrandom on Linux 3.17+ In a way, that's still part of CVE-2016-5300. https://github.com/libexpat/libexpat/pull/30/commits - [MOX-005] For the low quality entropy extraction fallback code, the parser instance address can no longer leak, - [MOX-003] Prevent use of uninitialised variable; commit - [MOX-004] a4dc944f37b664a3ca7199c624a98ee37babdb4b Add missing parameter validation to public API functions and dedicated error code XML_ERROR_INVALID_ARGUMENT: - [MOX-006] * NULL checks; commits * Negative length (XML_Parse); commit - [MOX-002] 70db8d2538a10f4c022655d6895e4c3e78692e7f - [MOX-001] #35 Change hash algorithm to William Ahern's version of SipHash to go further with fixing CVE-2012-0876. https://github.com/libexpat/libexpat/pull/39/commits - Bug fixes: #32 Fix sharing of hash salt across parsers; relevant where XML_ExternalEntityParserCreate is called prior to XML_Parse, in particular (e.g. FBReader) #28 xmlwf: Auto-disable use of memory-mapping (and parsing as a single chunk) for files larger than ~1 GB (2^30 bytes) rather than failing with error "out of memory" #3 Fix double free after malloc failure in DTD code; commit 7ae9c3d3af433cd4defe95234eae7dc8ed15637f #17 Fix memory leak on parser error for unbound XML attribute prefix with new namespaces defined in the same tag; found by Google's OSS-Fuzz; commits xmlwf on Windows: Add missing calls to CloseHandle - New features: #30 Introduced environment switch EXPAT_ENTROPY_DEBUG=1 for runtime debugging of entropy extraction Bump version info from 7:2:6 to 7:3:6 ------------------------------------------------------------------- Mon Jul 18 23:02:23 UTC 2016 - jengelh@inai.de - Remove pointless --with-pic (for static only) ------------------------------------------------------------------- Thu Jul 14 08:43:31 UTC 2016 - tchvatal@suse.com - Version update to 2.2.0: * Fixes bnc#983215 CVE-2012-6702 * Fixes bnc#983216 CVE-2016-5300 * Various cmake and autotools script updates * Fix detection of utf8 character boundaries - Remove all patches merged upstream: * expat-2.1.1-avoid_relying_on_undef_behaviour.patch * expat-2.1.1-parser_crashes_on_malformed_input.patch * expat-alloc-size.patch * expat-visibility.patch ------------------------------------------------------------------- Wed May 18 11:43:51 UTC 2016 - kstreitova@suse.com - add expat-2.1.1-avoid_relying_on_undef_behaviour.patch to avoid relying on undefined behavior in the original CVE-2015-1283 fix [bnc#980391], [bnc#983985], [CVE-2016-4472] - add expat-2.1.1-parser_crashes_on_malformed_input.patch to fix Expat XML parser that mishandles certain kinds of malformed input documents [bnc#979441], [CVE-2016-0718] - use spec-cleaner to clean specfile ------------------------------------------------------------------- Fri Apr 1 16:32:27 UTC 2016 - crrodriguez@opensuse.org - After simplification of expat-visibility.patch, it became uneffective as no symbols are getting hidden. add -fvisibility=hidden to CFLAGS again. - expat-alloc-size.patch: fix braino, realloc()-like functions should not take __attribute__(malloc) ------------------------------------------------------------------- Wed Mar 23 08:31:29 UTC 2016 - idonmez@suse.com - Update to version 2.1.1 * Fixes CVE-2015-1283 — Multiple integer overflows in the XML_GetBuffer function * Fix potential null pointer dereference * Symbol XML_SetHashSalt was not exported * Output of xmlwf -h was incomplete * Document behavior of calling XML_SetHashSalt with salt 0 * Minor improvements to man page xmlwf(1) - Simplify expat-visibility.patch, refresh expat-alloc-size.patch - Drop config-guess-sub-update.patch, fixed upstream. ------------------------------------------------------------------- Sat Jul 11 12:10:03 UTC 2015 - mpluskal@suse.com - Cleanup spec file with spec-cleaner - Remove old ppc obsoletes/provides ------------------------------------------------------------------- Tue Mar 26 13:10:01 UTC 2013 - mmeister@suse.com - Added url as source. Please see http://en.opensuse.org/SourceUrls ------------------------------------------------------------------- Thu Feb 21 16:02:17 UTC 2013 - jengelh@inai.de - Sanitize description of expat (replace it with a more current one from the homepage) ------------------------------------------------------------------- Mon Feb 4 12:59:44 UTC 2013 - schwab@suse.de - Update config.guess/sub for aarch64 ------------------------------------------------------------------- Wed Jan 23 09:07:25 UTC 2013 - pgajdos@suse.com - fix of fix of [bnc#798644] - according to upstream changelog: - Improved ability to build without the configure-generated expat_config.h header. This is useful for applications which embed Expat rather than linking in the library. because I am not exactly sure about implication of this, rather use -DXML_HAVE_VISIBILITY in CFLAG_VISIBILITY in expat-visibility.patch ------------------------------------------------------------------- Tue Jan 22 12:40:02 UTC 2013 - jengelh@inai.de - Executing autoreconf requires autoconf BuildRequire ------------------------------------------------------------------- Fri Jan 18 08:53:33 UTC 2013 - pgajdos@suse.com - really hide private Xml* symbols [bnc#798644] * modified visibility.patch ------------------------------------------------------------------- Tue Apr 10 19:06:34 UTC 2012 - tabraham@novell.com - update to 2.1.0 - Bug Fixes: #1742315: Harmful XML_ParserCreateNS suggestion. #2895533: CVE-2012-1147 - Resource leak in readfilemap.c. #1785430: Expat build fails on linux-amd64 with gcc version>=4.1 -O3. #1983953, 2517952, 2517962, 2649838: Build modifications using autoreconf instead of buildconf.sh. #2815947, #2884086: OBJEXT and EXEEXT support while building. #1990430: CVE-2009-3720 - Parser crash with special UTF-8 sequences. #2517938: xmlwf should return non-zero exit status if not well-formed. #2517946: Wrong statement about XMLDecl in xmlwf.1 and xmlwf.sgml. #2855609: Dangling positionPtr after error. #2894085: CVE-2009-3560 - Buffer over-read and crash in big2_toUtf8(). #2958794: CVE-2012-1148 - Memory leak in poolGrow. #2990652: CMake support. #3010819: UNEXPECTED_STATE with a trailing "%" in entity value. #3206497: Unitialized memory returned from XML_Parse. #3287849: make check fails on mingw-w64. #3496608: CVE-2012-0876 - Hash DOS attack. - Patches: #1749198: pkg-config support. #3010222: Fix for bug #3010819. #3312568: CMake support. #3446384: Report byte offsets for attr names and values. - New Features / API changes: * Added new API member XML_SetHashSalt() that allows setting an intial value (salt) for hash calculations. This is part of the fix for bug #3496608 to randomize hash parameters. * When compiled with XML_ATTR_INFO defined, adds new API member XML_GetAttributeInfo() that allows retrieving the byte offsets for attribute names and values (patch #3446384). * Added CMake build system. See bug #2990652 and patch #3312568. * Added run-benchmark target to Makefile.in - relies on testdata module present in the same relative location as in the repository. ------------------------------------------------------------------- Tue Mar 6 03:01:08 UTC 2012 - tabraham@novell.com - update to 2.1.0 beta * refreshed expat-visibility.patch * removed obsolete expat-CVE-2009-3560.patch * removed obsolete expat-CVE-2009-2625.patch - hash table DOS attack fix - accumulated bug fixes and some changes to the build system - new conditional feature to make byte offsets for attributes and attribute names available ------------------------------------------------------------------- Sun Feb 12 14:42:34 UTC 2012 - crrodriguez@opensuse.org - Put libraries back to %{_libdir}, /usr merge project ------------------------------------------------------------------- Fri Dec 2 12:43:19 UTC 2011 - coolo@suse.com - add automake as buildrequire to avoid implicit dependency ------------------------------------------------------------------- Sun Oct 30 22:03:29 UTC 2011 - crrodriguez@opensuse.org - Hide non public symbols reusing existing win32 API export/imports - annotate malloc/realloc-like functions with attribute alloc_size to catch possible misuses in calling code. ------------------------------------------------------------------- Sun Sep 18 17:17:12 UTC 2011 - jengelh@medozas.de - Remove redundant/obsolete tags/sections from specfile (cf. packaging guidelines) - Use %_smp_mflags for parallel build - Add libexpat-devel to baselibs ------------------------------------------------------------------- Fri Feb 25 16:01:01 UTC 2011 - prusnak@opensuse.org - fix license (MIT) in spec file ------------------------------------------------------------------- Fri Jan 8 15:04:28 CET 2010 - prusnak@suse.cz - fix CVE-2009-3560.patch [bnc#566434] ------------------------------------------------------------------- Sun Dec 13 19:28:22 CET 2009 - jengelh@medozas.de - add baselibs.conf as a source ------------------------------------------------------------------- Fri Dec 4 15:43:29 CET 2009 - prusnak@suse.cz - fix DoS (CVE-2009-3560.patch) [bnc#558892] ------------------------------------------------------------------- Thu Oct 29 14:22:47 CET 2009 - prusnak@suse.cz - fix DoS (CVE-2009-2625.patch) [bnc#550664] ------------------------------------------------------------------- Sun Apr 5 15:45:49 CEST 2009 - crrodriguez@suse.de - test suite requires gcc-c++ to compile ------------------------------------------------------------------- Thu Feb 19 04:55:08 CET 2009 - crrodriguez@suse.de - remove static libraries, shouldnt be needed anymore. - run make check ------------------------------------------------------------------- Wed Dec 10 12:34:56 CET 2008 - olh@suse.de - use Obsoletes: -XXbit only for ppc64 to help solver during distupgrade (bnc#437293) ------------------------------------------------------------------- Thu Oct 30 12:34:56 CET 2008 - olh@suse.de - obsolete old -XXbit packages (bnc#437293) ------------------------------------------------------------------- Thu Apr 10 12:54:45 CEST 2008 - ro@suse.de - added baselibs.conf file to build xxbit packages for multilib support ------------------------------------------------------------------- Sat Jul 28 19:38:40 CEST 2007 - coolo@suse.de - fix devel symlink ------------------------------------------------------------------- Wed Jul 25 11:29:59 CEST 2007 - prusnak@suse.cz - move libraries from /usr/lib to /lib [#285472] - replace deprecated %run_ldconfig with /sbin/ldconfig ------------------------------------------------------------------- Thu Jun 7 16:46:32 CEST 2007 - prusnak@suse.cz - update to 2.0.1: ( from Changes ) * Fixed bugs #1515266, 1515600: The character data handler's calling of XML_StopParser() was not handled properly; if the parser was stopped and the handler set to NULL, the parser would segfault. * Fixed bug #1690883: Expat failed on EBCDIC systems as it assumed some character constants to be ASCII encoded. * Minor cleanups of the test harness. * Fixed xmlwf bug #1513566: "out of memory" error on file size zero. * Fixed outline.c bug #1543233: missing a final XML_ParserFree() call. * Fixes and improvements for Windows platform: bugs #1409451, #1476160, 1548182, 1602769, 1717322. * Build fixes for various platforms: HP-UX, Tru64, Solaris 9: patch #1437840, bug #1196180. All Unix: #1554618 (refreshed config.sub/config.guess). #1490371, #1613457: support both, DESTDIR and INSTALL_ROOT, without relying on GNU-Make specific features. #1647805: Patched configure.in to work better with Intel compiler. * Fixes to Makefile.in to have make check work correctly: bugs #1408143, #1535603, #1536684. * Added Open Watcom support: patch #1523242. ------------------------------------------------------------------- Tue Apr 17 18:49:10 CEST 2007 - prusnak@suse.cz - split libexpat1 and libexpat-devel subpackages [#260214] ------------------------------------------------------------------- Thu Oct 19 12:37:07 CEST 2006 - dmueller@suse.de - strip .la file ------------------------------------------------------------------- Wed Jan 25 21:30:10 CET 2006 - mls@suse.de - converted neededforbuild to BuildRequires ------------------------------------------------------------------- Fri Jan 13 00:21:55 CET 2006 - ro@suse.de - fixed file list for debuginfo package (do not pack all of libdir) ------------------------------------------------------------------- Wed Jan 11 17:43:46 CET 2006 - mjancar@suse.cz - update to 2.0.0 ------------------------------------------------------------------- Mon Jan 9 13:25:07 CET 2006 - mjancar@suse.cz - update to 2.0 pre release ------------------------------------------------------------------- Wed Nov 10 11:54:21 CET 2004 - ro@suse.de - fixed filelist ------------------------------------------------------------------- Mon Aug 09 16:26:05 CEST 2004 - tcrhak@suse.cz - update to 1.95.8 ------------------------------------------------------------------- Thu Feb 5 18:28:34 CET 2004 - kukuk@suse.de - Build as user ------------------------------------------------------------------- Thu Feb 05 18:00:24 CET 2004 - tcrhak@suse.cz - update to version 1.95.7 ------------------------------------------------------------------- Tue Feb 18 15:36:28 CET 2003 - tcrhak@suse.cz - in expat.h, declare enum XML_Status before using it; put into patch "...-header.diff" [bug #23742] ------------------------------------------------------------------- Mon Feb 17 18:05:52 CET 2003 - tcrhak@suse.cz - updated to version 1.95.6 ------------------------------------------------------------------- Sun Dec 22 18:21:13 CET 2002 - tcrhak@suse.cz - update to version 1.95.5 ------------------------------------------------------------------- Sat Jul 13 15:14:59 CEST 2002 - tcrhak@suse.cz - update to version 1.95.4 ------------------------------------------------------------------- Thu Mar 28 15:17:43 CET 2002 - tcrhak@suse.cz - added parameter --target to configure ------------------------------------------------------------------- Mon Jan 14 13:25:11 CET 2002 - rvasice@suse.cz - use %{_libdir} and %{_lib} ------------------------------------------------------------------- Tue Nov 20 18:41:35 CET 2001 - rvasice@suse.cz - fix URL in spec file ------------------------------------------------------------------- Wed Aug 15 19:54:16 CEST 2001 - rvasice@suse.cz - update to version 1.95.2 - spec file cleanup - added DESTDIR ------------------------------------------------------------------- Mon May 14 12:08:01 CEST 2001 - pblaha@suse.cz - fixed links for soname of libexpat.so* ------------------------------------------------------------------- Fri May 11 09:03:03 CEST 2001 - cihlar@suse.cz - fixed soname of libexpat.so.1.2 ------------------------------------------------------------------- Fri Jan 5 10:13:20 CET 2001 - pblaha@suse.cz - back on stable version 1.2 added build shared libexpat.so ------------------------------------------------------------------- Thu Jan 4 15:46:21 CET 2001 - pblaha@suse.cz - update on 1.95.1 on sourgeforge needed for midgard - new description ------------------------------------------------------------------- Thu Mar 9 11:01:23 CET 2000 - ke@suse.de - Don't "install" symlinks; use "cp"; reported by bs; proposed fix by ro. - Cleanup the spec file: better Group tag; more accurate files list. ------------------------------------------------------------------- Tue Nov 23 14:59:17 CET 1999 - ke@suse.de - first SuSE package: version 1.1. - apply Debian patch to build shared libs. - build libexpat.a.
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor