Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

libexpat1-2.5.0-2.11 RPM for i586

From OpenSuSE Ports Tumbleweed for i586

Name: libexpat1 Distribution: openSUSE Tumbleweed
Version: 2.5.0 Vendor: openSUSE
Release: 2.11 Build date: Mon Oct 9 08:34:10 2023
Group: System/Libraries Build host: i04-ch4a
Size: 177554 Source RPM: expat-2.5.0-2.11.src.rpm
Packager: http://bugs.opensuse.org
Url: https://libexpat.github.io
Summary: XML Parser Toolkit
Expat is an XML parser library written in C. It is a stream-oriented
parser in which an application registers handlers for things the
parser might find in the XML document (like start tags).

Provides

Requires

License

MIT

Changelog

* Sun Dec 11 2022 Andreas Stieger <andreas.stieger@gmx.de>
  - add upstream signing key and validate source signature
* Wed Oct 26 2022 David Anes <david.anes@suse.com>
  - Update to 2.5.0: (bsc#1204708)
    * Security fixes:
    - CVE-2022-43680 -- Fix heap use-after-free after overeager
      destruction of a shared DTD in function
      XML_ExternalEntityParserCreate in out-of-memory situations.
      Expected impact is denial of service or potentially arbitrary
      code execution.
    * Bug fixes:
    - Fix curruption from undefined entities
    - Fix case when parsing was suspended while processing nested
      entities
    - Stop leaking opening tag bindings after a closing tag mismatch
      error where a parser is reset through XML_ParserReset and then
      reused to parse
    - CMake: Fix generation of pkg-config file
    - MinGW|CMake: Fix static library name
    * Other changes:
    - Protect header expat_config.h from multiple inclusion
    - examples: Make use of XML_GetBuffer and be more consistent
      across examples
    - Address compiler warnings
    - Version info bumped from 9:9:8 to 9:10:8; see
      https://verbump.de/ for what these numbers do
* Tue Sep 20 2022 David Anes <david.anes@suse.com>
  - update to 2.4.9: (bsc#1203438)
    * Security fixes:
    - CVE-2022-40674 -- Heap use-after-free vulnerability in
      function doContent. Expected impact is denial of service
      or potentially arbitrary code execution.
    * Bug fixes:
    - MinGW: Fix mis-compilation for -D__USE_MINGW_ANSI_STDIO=0
    - docs: Fix documentation on effect of switch XML_DTD on
      symbol visibility in doc/reference.html
    * Other changes:
    - MinGW: Make fix-xmltest-log.sh drop more Wine bug output
    - Autotools: Sync CMake templates with CMake 3.22
    - CMake: Migrate from use of CMAKE_*_POSTFIX to
      dedicated variables EXPAT_*_POSTFIX to stop affecting
      other projects
    - Windows|CMake: Add missing -DXML_STATIC to test runners
      and fuzzers
    - Windows|CMake: Render .def file from a template to fix
      linking with -DEXPAT_DTD=OFF and/or -DEXPAT_ATTR_INFO=ON
    - MinGW|CMake: Apply MSVC .def file when linking
    - MinGW|CMake: Sync library name with GNU Autotools,
      i.e. produce libexpat-1.dll rather than libexpat.dll
      by default.  Filename libexpat.dll.a is unaffected.
    - MinGW|CMake: Set missing variable CMAKE_RC_COMPILER in
      toolchain file "cmake/mingw-toolchain.cmake" to avoid
      error "windres: Command not found" on e.g. Ubuntu 20.04
    - CMake: Unify inconsistent use of set() and option() in
      context of public build time options to take need for
      set(.. FORCE) in projects using Expat by means of
      add_subdirectory(..) off Expat's users' shoulders
    - Stop exporting API symbols when building a static library
    - Resolve use of deprecated "fgrep" by "grep -F"
    - CMake: Make documentation on variables a bit more consistent
    - CMake: Drop leading whitespace from a #cmakedefine line in
      file expat_config.h.cmake
    - xmlwf: Fix harmless variable mix-up in function nsattcmp
    - Address Cppcheck warnings
    - Address Clang 15 compiler warnings
    - Version info bumped from 9:8:8 to 9:9:8;
      see https://verbump.de/ for what these numbers do
    * Infrastructure:
    - CI: Windows: Start covering MSVC 2022
    - CI: macOS: Migrate off deprecated macOS 10.15
    - CI: Linux: Make migration off deprecated Ubuntu 18.04 work
    - CI: Upgrade Clang from 14 to 15
    - apply-clang-format.sh: Add support for BSD find
    - coverage.sh: Exclude MinGW headers
    - coverage.sh: Fix name collision for -funsigned-char
* Tue Mar 29 2022 David Anes <david.anes@suse.com>
  - update to 2.4.8:
    * Other changes:
    - pkg-config: Move "-lm" to section "Libs.private"
    - CMake|MSVC: Fix pkg-config section "Libs"
    - CMake|macOS: Start using linker arguments
      "-compatibility_version <version>" and
      "-current_version <version>" in a way compatible with GNU
      Libtool
    - Version info bumped from 9:7:8 to 9:8:8;
      see https://verbump.de/ for what these numbers do
* Sat Mar 05 2022 David Anes <david.anes@suse.com>
  - update to 2.4.7 (bsc#1196784, CVE-2022-25236):
    * Bug fixes:
    - Relax fix to CVE-2022-25236 (introduced with release 2.4.5)
      with regard to all valid URI characters (RFC 3986),
      i.e. the following set (excluding whitespace):
      ABCDEFGHIJKLMNOPQRSTUVWXYZ abcdefghijklmnopqrstuvwxyz
      0123456789 % -._~ :/?#[]@ !$&'()*+,;=
    * Other changes:
    - CMake|Windows: Store Expat version in the DLL
    - Document consequences of namespace separator choices not just
      in doc/reference.html but also in header <expat.h>
    - Document Expat's lack of validation of namespace URIs against
      RFC 3986, and that the XML 1.0r4 specification doesn't
      require Expat to validate namespace URIs, and that Expat
      may do more in that regard in future releases.
      If you find need for strict RFC 3986 URI validation on
      application level today, https://uriparser.github.io/ may
      be of interest.
    - Fix documentation of XML_EndDoctypeDeclHandler in <expat.h>
    - Document that a call to XML_FreeContentModel can be done at
      a later time from outside the element declaration handler
    - Make hardcoded namespace URIs easier to find in code
    - Update documentation on use of XML_POOR_ENTOPY on Solaris
    - tests: Resolve use of macros NAN and INFINITY for GNU G++
      4.8.2 on Solaris.
    - Version info bumped from 9:6:8 to 9:7:8;
      see https://verbump.de/ for what these numbers do
* Sun Feb 20 2022 David Anes <david.anes@suse.com>
  - update to 2.4.6 (bsc#1196168, CVE-2022-25313):
    * Bug fixes:
    - Fix a regression introduced by the fix for CVE-2022-25313
      in release 2.4.5 that affects applications that (1)
      call function XML_SetElementDeclHandler and (2) are
      parsing XML that contains nested element declarations
      (e.g. "<!ELEMENT junk ((bar|foo|xyz+), zebra*)>").
    - Version info bumped from 9:5:8 to 9:6:8;
      see https://verbump.de/ for what these numbers do.
* Sat Feb 19 2022 David Anes <david.anes@suse.com>
  - update to 2.4.5 (bsc#1196171, bsc#1196169, bsc#1196168,
    bsc#1196026, bsc#1196025):
    * Security fixes:
    - CVE-2022-25235 -- Passing malformed 2- and 3-byte UTF-8
      sequences (e.g. from start tag names) to the XML
      processing application on top of Expat can cause
      arbitrary damage (e.g. code execution) depending
      on how invalid UTF-8 is handled inside the XML
      processor; validation was not their job but Expat's.
      Exploits with code execution are known to exist.
    - CVE-2022-25236 -- Passing (one or more) namespace separator
      characters in "xmlns[:prefix]" attribute values
      made Expat send malformed tag names to the XML
      processor on top of Expat which can cause
      arbitrary damage (e.g. code execution) depending
      on such unexpectable cases are handled inside the XML
      processor; validation was not their job but Expat's.
      Exploits with code execution are known to exist.
    - CVE-2022-25313 -- Fix stack exhaustion in doctype parsing
      that could be triggered by e.g. a 2 megabytes
      file with a large number of opening braces.
      Expected impact is denial of service or potentially
      arbitrary code execution.
    - CVE-2022-25314 -- Fix integer overflow in function copyString;
      only affects the encoding name parameter at parser creation
      time which is often hardcoded (rather than user input),
      takes a value in the gigabytes to trigger, and a 64-bit
      machine.  Expected impact is denial of service.
    - CVE-2022-25315 -- Fix integer overflow in function storeRawNames;
      needs input in the gigabytes and a 64-bit machine.
      Expected impact is denial of service or potentially
      arbitrary code execution.
    * Other changes:
    - Version info bumped from 9:4:8 to 9:5:8;
      see https://verbump.de/ for what these numbers do
* Mon Jan 31 2022 David Anes <david.anes@suse.com>
  - update to 2.4.4 (bsc#1195217, bsc#1195054):
    * Security fixes:
    - CVE-2022-23852 -- Fix signed integer overflow
      (undefined behavior) in function XML_GetBuffer
      that is also called by function XML_Parse internally)
      for when XML_CONTEXT_BYTES is defined to >0 (which is both
      common and default).
      Impact is denial of service or more.
    - CVE-2022-23990 -- Fix unsigned integer overflow in function
      doProlog triggered by large content in element type
      declarations when there is an element declaration handler
      present (from a prior call to XML_SetElementDeclHandler).
      Impact is denial of service or more.
    * Bug fixes:
    - xmlwf: Fix a memory leak on output file opening error
    * Other changes:
    - Version info bumped from 9:3:8 to 9:4:8;
      see https://verbump.de/ for what these numbers do
    * Drop unused file valid-xhtml10.png
* Mon Jan 17 2022 Dirk Müller <dmueller@suse.com>
  - update to 2.4.3 (bsc#1194251, bsc#1194362, bsc#1194474,
      bsc#1194476, bsc#1194477, bsc#1194478, bsc#1194479, bsc#1194480):
    * CVE-2021-45960 -- Fix issues with left shifts by >=29 places
      resulting in
      a) realloc acting as free
      b) realloc allocating too few bytes
      c) undefined behavior
      depending on architecture and precise value
      for XML documents with >=2^27+1 prefixed attributes
      on a single XML tag a la
      "<r xmlns:a='[..]' a:a123='[..]' [..] />"
      where XML_ParserCreateNS is used to create the parser
      (which needs argument "-n" when running xmlwf).
      Impact is denial of service, or more.
    * CVE-2021-46143 (ZDI-CAN-16157) -- Fix integer overflow
      on variable m_groupSize in function doProlog leading
      to realloc acting as free.
      Impact is denial of service or more.
    * CVE-2022-22822 to CVE-2022-22827 -- Prevent integer overflows
      near memory allocation at multiple places.  Mitre assigned
      a dedicated CVE for each involved internal C function:
    - CVE-2022-22822 for function addBinding
    - CVE-2022-22823 for function build_model
    - CVE-2022-22824 for function defineAttribute
    - CVE-2022-22825 for function lookup
    - CVE-2022-22826 for function nextScaffoldPart
    - CVE-2022-22827 for function storeAtts
      Impact is denial of service or more.
* Mon Dec 27 2021 Dirk Müller <dmueller@suse.com>
  - update to 2.4.2:
    * Link againgst libm for function "isnan"
    * Include expat_config.h as early as possible
    * Autotools: Include files with release archives:
    - buildconf.sh
    - fuzz/*.c
    * Autotools: Sync CMake templates
    * docs: Document that function XML_GetBuffer may return NULL
      when asking for a buffer of 0 (zero) bytes size
    * docs: Fix return value docs for both
      XML_SetBillionLaughsAttackProtection* functions
    * Version info bumped from 9:1:8 to 9:2:8
* Mon May 24 2021 Pedro Monreal <pmonreal@suse.com>
  - Update to 2.4.1:
    * Bug fixes:
    - Autotools: Fix installed header expat_config.h for multilib
      systems; regression introduced in 2.4.0 by pull request #486
    * Other changes:
    - Version info bumped from 9:0:8 to 9:1:8; see
      https://verbump.de/ for what these numbers do
* Mon May 24 2021 Pedro Monreal <pmonreal@suse.com>
  - Update to 2.4.0: [CVE-2013-0340 "Billion Laughs"]
    * Security fixes:
    - CVE-2013-0340/CWE-776 -- Protect against billion laughs attacks
      (denial-of-service; flavors targeting CPU time or RAM or both,
      leveraging general entities or parameter entities or both)
      by tracking and limiting the input amplification factor
      (<amplification> := (<direct> + <indirect>) / <direct>).
      By conservative default, amplification up to a factor of 100.0
      is tolerated and rejection only starts after 8 MiB of output bytes
      (=<direct> + <indirect>) have been processed.
      The fix adds the following to the API:
    - A new error code XML_ERROR_AMPLIFICATION_LIMIT_BREACH to
      signals this specific condition.
    - Two new API functions ..
    - XML_SetBillionLaughsAttackProtectionMaximumAmplification and
    - XML_SetBillionLaughsAttackProtectionActivationThreshold
      .. to further tighten billion laughs protection parameters
      when desired.  Please see file "doc/reference.html" for details.
      If you ever need to increase the defaults for non-attack XML
      payload, please file a bug report with libexpat.
    - Two new XML_FEATURE_* constants ..
    - that can be queried using the XML_GetFeatureList function, and
    - that are shown in "xmlwf -v" output.
    - Two new environment variable switches ..
    - EXPAT_ACCOUNTING_DEBUG=(0|1|2|3) and
    - EXPAT_ENTITY_DEBUG=(0|1)
      .. for runtime debugging of accounting and entity processing.
      Specific behavior of these values may change in the future.
    - Two new command line arguments "-a FACTOR" and "-b BYTES"
      for xmlwf to further tighten billion laughs protection
      parameters when desired.
      If you ever need to increase the defaults for non-attack XML
      payload, please file a bug report with libexpat.
    * Bug fixes:
    - For (non-default) compilation with -DEXPAT_MIN_SIZE=ON (CMake)
      or CPPFLAGS=-DXML_MIN_SIZE (GNU Autotools): Fix segfault
      for UTF-16 payloads containing CDATA sections.
    - Autotools: Fix generated CMake files for non-64bit and
      non-Linux platforms (e.g. macOS and MinGW in particular)
      that were introduced with release 2.3.0
    * Other changes:
    - xmlwf: Improve help output and the xmlwf man page
    - xmlwf: Improve maintainability through some refactoring
    - xmlwf: Fix man page DocBook validity
    - CMake: Support absolute paths for both CMAKE_INSTALL_LIBDIR
      and CMAKE_INSTALL_INCLUDEDIR
    - CMake: Add support for standard variable BUILD_SHARED_LIBS
    - Unexpose symbol _INTERNAL_trim_to_complete_utf8_characters
    - Resolve macro HAVE_EXPAT_CONFIG_H
    - Delete unused legacy helper file "conftools/PrintPath"
    - doc/reference.html: Fix XHTML validity
    - doc/reference.html: Replace the 90s look by OK.css
    - Version info bumped from 8:0:7 to 9:0:8 due to addition of
      new symbols and error codes; see https://verbump.de/ for
      what these numbers do
* Tue Apr 13 2021 Dominique Leuenberger <dimstar@opensuse.org>
  - Do not BuildRequire cmake: expat is part of the distro bootstrap
    cycle and any additional dependency makes the ring larger. In
    this case here, cmake was even only used to own a directory.
* Tue Apr 06 2021 Dirk Müller <dmueller@suse.com>
  - update to 2.3.0:
    * When calling XML_ParseBuffer without a prior successful call to
      XML_GetBuffer as a user, no longer trigger undefined behavior
      (by adding an integer to a NULL pointer) but rather return
      XML_STATUS_ERROR and set the error code to (new) code
      XML_ERROR_NO_BUFFER. Found by UBSan (UndefinedBehaviorSanitizer)
      of Clang 11 (but not Clang 9).
    * xmlwf: Exit status 2 was used for both:
    - malformed input files (documented) and
    - invalid command-line arguments (undocumented).
      case of invalid command-line arguments now
      has its own exit status 4, resolving the ambiguity.
    * Other changes
* Sun Oct 04 2020 Pedro Monreal <pmonreal@suse.com>
  - Update to 2.2.10:
    * Bug fixes:
    - Fix undefined behavior during parsing caused by pointer
      arithmetic with NULL pointers
    - Fix reading uninitialized variable during parsing
    - xmlwf: Add missing check for malloc NULL return
    * Other changes:
    - xmlwf: Document exit codes in xmlwf manpage and exit with code 3
      (rather than code 1) for output errors when used with "-d DIRECTORY"
    - Autotools: Use -Werror while configure tests the compiler for
      supported compile flags to avoid false positives
    - Autotools: Improve handling of user (C|CPP|CXX|LD)FLAGS, e.g.
      ensure that they have the last word over flags added while
      running ./configure
    - CMake: Create libexpatw.{dll,so} and expatw.pc (with emphasis
      on suffix "w") with -DEXPAT_CHAR_TYPE=(ushort|wchar_t)
    - CMake: Detect and deny unsupported build combinations
      involving -DEXPAT_CHAR_TYPE=(ushort|wchar_t)
    - CMake: Install pre-compiled shipped xmlwf.1 manpage in case
      of -DEXPAT_BUILD_DOCS=OFF
    - CMake: Fix use of Expat by means of add_subdirectory
    - CMake: Keep expat target name constant at "expat" (i.e. refrain
      from using the target name to control build artifact filenames)
    - CMake: Expose man page compilation as target "xmlwf-manpage"
    - CMake: Introduce option EXPAT_BUILD_PKGCONFIG to control
      generation of pkg-config file "expat.pc"
    - CMake: Add minimalistic support for building binary packages
      with CMake target "package"; based on CPack
    - CMake: Add option -DEXPAT_OSSFUZZ_BUILD=(ON|OFF) with default
      OFF to build fuzzer code against OSS-Fuzz and related
      environment variable LIB_FUZZING_ENGINE
    - Fix testsuite for -DEXPAT_DTD=OFF and -DEXPAT_NS=OFF
    - Address compiler warnings
    - Address pngcheck warnings with doc/*.png images: Version info
      bumped from 7:11:6 to 7:12:6

Files

/usr/lib/libexpat.so.1
/usr/lib/libexpat.so.1.8.10


Generated by rpm2html 1.8.1

Fabrice Bellet, Fri Jan 26 23:39:43 2024