From fb6f17c37a9c46a841b7426efbc1d2f333f58dea Mon Sep 17 00:00:00 2001 From: MSVSphere Packaging Team Date: Thu, 23 May 2024 13:20:47 +0300 Subject: [PATCH] import expat-2.2.5-13.el8_10 --- SPECS/expat.spec | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/SPECS/expat.spec b/SPECS/expat.spec index f327f6e..f91c30b 100644 --- a/SPECS/expat.spec +++ b/SPECS/expat.spec @@ -3,7 +3,7 @@ Summary: An XML parser library Name: expat Version: %(echo %{unversion} | sed 's/_/./g') -Release: 11%{?dist}.1 +Release: 13%{?dist} Source: https://github.com/libexpat/libexpat/archive/R_%{unversion}.tar.gz#/expat-%{version}.tar.gz URL: https://libexpat.github.io/ License: MIT @@ -114,9 +114,13 @@ make check %{_libdir}/lib*.a %changelog -* Mon Mar 25 2024 Tomas Korbar - 2.2.5-11.1 +* Tue Mar 26 2024 Tomas Korbar - 2.2.5-12 - CVE-2023-52425 expat: parsing large tokens can trigger a denial of service -- Resolves: RHEL-29320 +- Resolves: RHEL-29321 * Mon Nov 14 2022 Tomas Korbar - 2.2.5-11 - CVE-2022-43680 expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate