Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-10 Thread Moritz Muehlenhoff
On Mon, Jun 09, 2014 at 09:01:46PM +1000, Hamish Moffatt wrote: On 09/06/14 15:17, Salvatore Bonaccorso wrote: Hi, On Sun, Jun 01, 2014 at 11:30:15PM -0300, Lisandro Damián Nicanor Pérez Meyer wrote: tag 750141 moreinfo thanks On Monday 02 June 2014 11:19:05 Hamish Moffatt wrote:

Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-09 Thread Hamish Moffatt
On 09/06/14 15:17, Salvatore Bonaccorso wrote: Hi, On Sun, Jun 01, 2014 at 11:30:15PM -0300, Lisandro Damián Nicanor Pérez Meyer wrote: tag 750141 moreinfo thanks On Monday 02 June 2014 11:19:05 Hamish Moffatt wrote: Package: libqt4-xml Severity: serious Tags: security Justification:

Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-08 Thread Salvatore Bonaccorso
Hi, On Sun, Jun 01, 2014 at 11:30:15PM -0300, Lisandro Damián Nicanor Pérez Meyer wrote: tag 750141 moreinfo thanks On Monday 02 June 2014 11:19:05 Hamish Moffatt wrote: Package: libqt4-xml Severity: serious Tags: security Justification: security Qt 4.8.6 has a fix for a denial

Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-01 Thread Hamish Moffatt
Package: libqt4-xml Severity: serious Tags: security Justification: security Qt 4.8.6 has a fix for a denial of service attack due to XML entity expansion (billion laughs attack). This fix doesn't seem to be in the wheezy packages yet. http://blog.qt.digia.com/blog/2014/04/24/qt-4-8-6-released/

Bug#750141: libqt4-xml: vulnerable to billion laughs attack

2014-06-01 Thread Lisandro Damián Nicanor Pérez Meyer
tag 750141 moreinfo thanks On Monday 02 June 2014 11:19:05 Hamish Moffatt wrote: Package: libqt4-xml Severity: serious Tags: security Justification: security Qt 4.8.6 has a fix for a denial of service attack due to XML entity expansion (billion laughs attack). This fix doesn't seem to be