Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update bundled libexpat dependency to v2.2.1 #176

Merged
merged 1 commit into from
Jul 5, 2017
Merged

Update bundled libexpat dependency to v2.2.1 #176

merged 1 commit into from
Jul 5, 2017

Conversation

lovell
Copy link
Contributor

@lovell lovell commented Jun 23, 2017

Hello, this will address CVE-2017-9233, a denial-of-service vulnerability that can be triggered by a malicious external entity DTD.

There were a number of files present in deps/libexpat that are no longer present in the official libexpat release tarball, hence the apparent removal of 10K LOC by this PR.

See #175

@lovell
Copy link
Contributor Author

lovell commented Jun 23, 2017

Opened PR #177 to deal with the unrelated Travis CI failures.

@astro
Copy link
Collaborator

astro commented Jul 5, 2017

Thank you very much!

@lovell lovell deleted the libexpat-2.2.1 branch July 5, 2017 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants