summaryrefslogtreecommitdiff
path: root/expat
Commit message (Expand)AuthorAgeFilesLines
* Changes: Document CVE-2022-25235Sebastian Pipping2022-02-181-0/+7
* tests: Cover missing validation of encoding (CVE-2022-25235)Sebastian Pipping2022-02-181-0/+109
* lib: Add comments to BT_LEAD* cases where encoding has already been validatedSebastian Pipping2022-02-181-5/+5
* lib: Add missing validation of encoding (CVE-2022-25235)Sebastian Pipping2022-02-181-2/+6
* lib: Drop unused macro UTF8_GET_NAMINGSebastian Pipping2022-02-181-5/+0
* Merge pull request #561 from libexpat/namesep-securitySebastian Pipping2022-02-183-4/+59
|\
| * Changes: Document CVE-2022-25236Sebastian Pipping2022-02-161-0/+16
| * tests: Cover CVE-2022-25236Sebastian Pipping2022-02-161-0/+30
| * lib: Protect against malicious namespace declarations (CVE-2022-25236)Sebastian Pipping2022-02-161-0/+11
| * lib: Fix (harmless) use of uninitialized memorySebastian Pipping2022-02-161-4/+2
* | Merge pull request #560 from ferivoz/copySebastian Pipping2022-02-181-1/+1
|\ \
| * | Prevent integer overflow in copyStringSamanta Navarro2022-02-151-1/+1
* | | Merge pull request #559 from ferivoz/rawnamesSebastian Pipping2022-02-181-1/+6
|\ \ \
| * | | Prevent integer overflow in storeRawNamesSamanta Navarro2022-02-151-1/+6
| |/ /
* | | Merge pull request #558 from ferivoz/modelSebastian Pipping2022-02-181-37/+79
|\ \ \ | |_|/ |/| |
| * | Prevent stack exhaustion in build_modelSamanta Navarro2022-02-151-37/+79
| |/
* | Sync file headersSebastian Pipping2022-02-159-9/+9
|/
* win32: Add missing files to the installerSebastian Pipping2022-01-292-0/+7
* doc: Drop unused file valid-xhtml10.pngSebastian Pipping2022-01-293-2/+0
* .gitignore: Add missingSebastian Pipping2022-01-291-0/+1
* xmlwf.xml: Adapt note to current practiceSebastian Pipping2022-01-291-1/+1
* Set expected release date for 2.4.4Sebastian Pipping2022-01-292-2/+2
* Sync file headersSebastian Pipping2022-01-293-2/+3
* Bump version to 2.4.4Sebastian Pipping2022-01-298-13/+13
* Bump version info from 9:3:8 to 9:4:8Sebastian Pipping2022-01-293-2/+4
* Changes: Document #546Sebastian Pipping2022-01-291-0/+4
* Stop casting void* results from calls to .malloc_fcn (#553)czentgr2022-01-291-8/+8
* Changes: Document CVE-2022-23990Sebastian Pipping2022-01-261-0/+6
* lib: Prevent integer overflow in doProlog (CVE-2022-23990)Sebastian Pipping2022-01-261-2/+8
* xmlwf: Fix a memory leak on output file opening errorSebastian Pipping2022-01-242-2/+8
* Changes: Document CVE-2022-23852prevent-getbuffer-overflowSebastian Pipping2022-01-241-0/+12
* tests: Cover integer overflow in XML_GetBuffer (CVE-2022-23852)Sebastian Pipping2022-01-241-0/+27
* lib: Detect and prevent integer overflow in XML_GetBuffer (CVE-2022-23852)Samanta Navarro2022-01-241-0/+5
* Fix typosSamanta Navarro2022-01-223-4/+4
* [>=2.3.0] Autotools: Fix broken CMake support under Cygwin (#546)Carlo Bramini2022-01-202-3/+11
* Set expected release date for 2.4.3issue-533-prepare-releaseSebastian Pipping2022-01-132-2/+2
* Changes: Streamline item order for 2.4.3Sebastian Pipping2022-01-131-1/+1
* Changes: Document #528 and #529Sebastian Pipping2022-01-131-0/+3
* Sync years in file headersSebastian Pipping2022-01-1311-11/+11
* Bump version to 2.4.3Sebastian Pipping2022-01-138-13/+13
* Bump version info from 9:2:8 to 9:3:8Sebastian Pipping2022-01-133-2/+4
* Changes: Document CVE-2022-22822 to CVE-2022-22827prevent-more-integer-overflowsSebastian Pipping2022-01-121-0/+10
* lib: Prevent integer overflow at multiple places (CVE-2022-22822 to CVE-2022-...Sebastian Pipping2022-01-121-2/+151
* Changes: Document integer overflow CVE-2021-46143Sebastian Pipping2022-01-101-0/+6
* lib: Prevent integer overflow on m_groupSize in function doProlog (CVE-2021-4...Sebastian Pipping2022-01-101-0/+15
* run.sh.in: Do not use Wine with Cygwin and MSYS2fix-run-sh-in-for-native-windowsSebastian Pipping2022-01-092-1/+14
* Changes: Document CVE-2021-45960issue-531-troublesome-shiftsSebastian Pipping2022-01-051-0/+19
* lib: Detect and prevent troublesome left shifts in function storeAtts (CVE-20...Sebastian Pipping2022-01-051-2/+29
* Actions: Check for realistic minimum CMake version requirementactions-cover-cmake-required-versionSebastian Pipping2022-01-011-0/+3
* CMake: Make call to file(GENERATE [..]) work for CMake <3.19cmake-fix-call-to-file-generateSebastian Pipping2021-12-313-9/+9