HomeFreeBSD

textproc/libxml2: update to 2.10.14 security release (+)

Description

textproc/libxml2: update to 2.10.14 security release (+)

  • [CVE-2023-29469] Hashing of empty dict strings isn't deterministic
  • [CVE-2023-28484] Fix null deref in xmlSchemaFixupComplexType
  • schemas: Fix null-pointer-deref in xmlSchemaCheckCOSSTDerivedOK
  • SAX2: Ignore namespaces in HTML documents
  • io: Fix "buffer full" error with certain buffer sizes

PR: 270906
Security: 0bd7f07b-dc22-11ed-bf28-589cfc0f81b0

Sponsored by: Serenity Cybersecurity, LLC

(cherry picked from commit acd6567eeccaba062051ae4571c3d20c355383ac)

Details

Provenance
fluffyAuthored on Apr 27 2023, 6:07 PM
Parents
R11:40a6b20c8e3e: www/grafana9: Security update to 9.4.9
Branches
Unknown
Tags
Unknown