50 Commits

Author SHA1 Message Date
Funda Wang
2abb988b9c fix CVE-2024-40896 2024-07-29 00:09:42 +08:00
cenhuilin
88ba0783c6 fix CVE-2024-34459 2024-05-17 09:38:28 +08:00
HuBin95
850edbcb3d 回退 'Pull Request !224 : upgrade to upstream v2.12.5'
(cherry picked from commit cb08a52eeb9a45816bcfd044d1807bca8c03f176)
2024-03-09 16:51:59 +08:00
Zhipeng Xie
69b9597f3a upgrade to v2.12.5
Signed-off-by: Zhipeng Xie <xiezhipeng1@huawei.com>
2024-02-28 10:49:42 +08:00
liweigang
cacc39cb49 fix CVE-2024-25062
Signed-off-by: liweigang <liweiganga@uniontech.com>
2024-02-05 11:02:18 +08:00
zhuofeng
806eeb71a3 update version to 2.11.5 2024-01-29 16:57:29 +08:00
Zhipeng Xie
b95796e11b backport upstream patches
Signed-off-by: Zhipeng Xie <xiezhipeng1@huawei.com>
2023-12-31 21:55:52 +08:00
BruceGW
5759da88e3 fix CVE-2023-45322
Signed-off-by: BruceGW <gyl93216@163.com>
2023-10-16 14:48:44 +08:00
Chenxi Mao
0cbc2d9f78 Enable ftp by default
libxml2 disabled ftp by defult since a0a0f3be93753e387e31e7de95904a24b3c876dd.
However, open-vm-tools depend on this feature.
So enable ftp to make open-vm-tools happy.

Link: a0a0f3be93
2023-09-14 22:08:28 +08:00
zhuofeng
eb08f2a86a update doc/example file 2023-08-07 18:55:46 +08:00
zhuofeng
73501ef026 fix failed test 2023-08-07 11:07:29 +08:00
zhuofeng
9789a518b5 update version to 2.11.4 2023-07-20 16:25:23 +08:00
BruceGW
a5c2f6879e fix 2023-28484 CVE-2023-29469
Signed-off-by: BruceGW <gyl93216@163.com>
2023-04-20 22:07:36 +08:00
Zhipeng Xie
6a272753c8 backport upstream patches
Signed-off-by: Zhipeng Xie <xiezhipeng1@huawei.com>
2023-02-27 19:39:37 +08:00
Zhipeng Xie
1513472492 backport upstream patches
Signed-off-by: Zhipeng Xie <xiezhipeng1@huawei.com>
2022-11-29 15:28:15 +08:00
Zhipeng Xie
44c151e7b3 update patch names
Signed-off-by: Zhipeng Xie <xiezhipeng1@huawei.com>
2022-11-29 14:39:34 +08:00
Wentao Fan
0ac3039c45 backport upstream patches
Signed-off-by: Wentao Fan <fanwentao@huawei.com>
2022-11-29 11:10:08 +08:00
fly_fzc
60c724d23d backport upstream patches 2022-11-21 10:40:23 +08:00
fly_fzc
43ef647224 fix CVE-2022-40303 CVE-2022-40304 2022-11-08 17:04:45 +08:00
fly_fzc
27cb18f9d0 Fix Obsoletes in spec 2022-09-13 09:14:10 +08:00
fly_fzc
b8bc4e4ffd Upgrade to upstream v2.9.14 and Cleanup duplicate installation 2022-07-13 10:34:07 +08:00
fuanan
1f2c813141 Fix memory leaks in xmlACatalogAdd when xmlHashAddEntry failed 2022-06-24 10:05:06 +08:00
fuanan
136ca1dd79 Fix memory leaks for xmlACatalogAdd 2022-06-16 20:05:05 +08:00
fuanan
b3c3367374 fix CVE-2022-29824 2022-05-09 09:27:00 +08:00
fuanan
a76b336045 fix CVE-2022-23308 2022-03-09 11:41:05 +08:00
fuanan
adf0ba7094 use upstream patch refix heap-use-after-free in xmlAddNextSibling and xmlAddChild 2022-02-11 14:28:50 +08:00
panxiaohe
0c79c44132 add backport bug fixes 2021-11-12 17:25:21 +08:00
panxiaohe
0439350149 Fix heap-use-after-free in xmlAddNextSibling and xmlAddChild 2021-11-11 17:05:54 +08:00
Zhipeng Xie
41b0da9246 upgrade to upstream v2.9.12
Signed-off-by: Zhipeng Xie <xiezhipeng1@huawei.com>
2021-11-10 14:50:37 +08:00
panxiaohe
12f1fc76cb fix memleaks in xmlXIncludeProcessFlags 2021-11-09 17:28:11 +08:00
huangduirong
7d42827878 fix null deref in xmlSchemaGetComponentTargetNs 2021-10-30 16:20:21 +08:00
panxiaohe
b13dc221f9 fix fuzz issues 2021-10-23 17:19:05 +08:00
panxiaohe
311df5fe76 fix fuzz issues 2021-10-21 17:51:09 +08:00
guoxiaoqi
a66e512517 fix CVE-2021-3541 2021-06-02 10:50:10 +08:00
zou_lin77
f344b07742 add patches from upstream 2021-05-29 17:30:59 +08:00
guoxiaoqi
5ca61341cd fix CVE-2021-3517 and CVE-2021-3518 2021-05-28 11:28:23 +08:00
yangkang
39311827e9 fix CVE-2021-3537 2021-05-27 16:42:35 +08:00
Liquor
5a155f4191 fix problems detected by oss-fuzz test 2021-03-02 19:53:18 +08:00
Liquor
adec381a8b fix problems detected by oss-fuzz test 2020-11-12 10:24:05 +08:00
panxiaohe
6124e28edb remove subpackage python2-libxml2 2020-10-29 16:54:03 +08:00
yang_zhuang_zhuang
29fcec1b58 revert Don-t-try-to-handle-namespaces-when-building-HTML-do.patch 2020-09-14 16:38:30 +08:00
yang_zhuang_zhuang
04bbcc0db4 Fixed some issues found in fuzzing testcases 2020-09-10 10:31:12 +08:00
zou_lin77
e81785b5f3 Fix more quadratic runtime issues in HTML push parse
Fix reset HTML parser input before reporting error
2020-08-28 18:30:14 +08:00
liquor
810ab7f2f3 Limit regexp nesting depth and Fix exponential runtime in xmlFARecurseDeterminism 2020-08-12 19:19:37 +08:00
liquor
57fff5b42d Fix integer overflow in xmlFAParseQuantExact 2020-08-03 18:42:48 +08:00
Yangyang Shen
1eab2e063e Fix use after free with validating render 2020-07-28 10:14:21 +08:00
wangchen2020
e77c487eb2 Sync some patches from community 2020-07-03 16:56:41 +08:00
chengquan
bb231caccf upgrade software to v2.9.10 2020-05-11 15:09:02 +08:00
wsp1991
ebcc4287e9 Sync some patches from community 2020-03-17 21:03:10 +08:00
dogsheng
7225a592c9 Package init 2019-12-25 17:13:34 +08:00