Bug#1010526: [xml/sgml-pkgs] Bug#1010526: libxml2: CVE-2022-29824: integer overflows in xmlBuf and xmlBuffer

2022-05-05 Thread Mattia Rizzolo
On Tue, May 03, 2022 at 05:43:50PM +0200, Salvatore Bonaccorso wrote: > CVE-2022-29824[0]: > | In libxml2 before 2.9.14, I'm uploading 2.9.14 in a few minutes, taking care of this for unstable and bookworm, but if you believe this bug deserves to be fixed through -security, I'd ask if you can

Bug#1010526: libxml2: CVE-2022-29824: integer overflows in xmlBuf and xmlBuffer

2022-05-03 Thread Salvatore Bonaccorso
Source: libxml2 Version: 2.9.13+dfsg-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for libxml2. CVE-2022-29824[0]: | In libxml2 before 2.9.14, several buffer handling functions in buf.c | (xmlBuf*)