summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSebastian Pipping <sebastian@pipping.org>2022-09-21 03:32:26 +0200
committerSebastian Pipping <sebastian@pipping.org>2022-10-24 14:58:45 +0200
commiteedc5f6de8e219130032c8ff2ff17580e18bd0c1 (patch)
tree26acd59d08f46d82e55135731bda8e32f988c5c8
parent43992e4ae25fc3dc0eec0cd3a29313555d56aee2 (diff)
downloadlibexpat-git-eedc5f6de8e219130032c8ff2ff17580e18bd0c1.tar.gz
Changes: Document #649
-rw-r--r--expat/Changes5
1 files changed, 5 insertions, 0 deletions
diff --git a/expat/Changes b/expat/Changes
index ea7d7e4c..6985707e 100644
--- a/expat/Changes
+++ b/expat/Changes
@@ -3,6 +3,11 @@ NOTE: We are looking for help with a few things:
If you can help, please get in touch. Thanks!
Release x.x.x xxx xxxxxxxxxxxx xx xxxx
+ Security fixes:
+ #616 #649 #650 CVE-2022-43680 -- Fix heap use-after-free after overeager
+ destruction of a shared DTD in function
+ XML_ExternalEntityParserCreate in out-of-memory situations
+
Bug fixes:
#612 #645 Fix curruption from undefined entities
#613 #654 Fix case when parsing was suspended while processing nested