From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: Received: from ptx.hi.pengutronix.de ([2001:67c:670:100:1d::c0]) by metis.ext.pengutronix.de with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from ) id 1fWGHs-00068O-SN for ptxdist@pengutronix.de; Fri, 22 Jun 2018 09:15:16 +0200 Received: from mol by ptx.hi.pengutronix.de with local (Exim 4.89) (envelope-from ) id 1fWGHs-0005Cc-Io for ptxdist@pengutronix.de; Fri, 22 Jun 2018 09:15:16 +0200 Date: Fri, 22 Jun 2018 09:15:16 +0200 From: Michael Olbrich Message-ID: <20180622071516.scs63brk76n5u4ef@pengutronix.de> References: <20180621112156.18333-1-Denis.Osterland@diehl.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20180621112156.18333-1-Denis.Osterland@diehl.com> Subject: Re: [ptxdist] [PATCH] libxml2: apply fix for CVE-2017-8872 List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: ptxdist-bounces@pengutronix.de Sender: "ptxdist" To: ptxdist@pengutronix.de T24gVGh1LCBKdW4gMjEsIDIwMTggYXQgMTE6MjU6MDNBTSArMDAwMCwgRGVuaXMgT1NURVJMQU5E IHdyb3RlOgo+IFRha2VuIGZyb20gZGViaWFuIGJ1c3RlciBsaWJ4bWwyXzIuOS43K2Rmc2ctMS4K PiAKPiBTaWduZWQtb2ZmLWJ5OiBEZW5pcyBPc3RlcmxhbmQgPERlbmlzLk9zdGVybGFuZEBkaWVo bC5jb20+Cj4gLS0tCj4gIC4uLi1ib3VuZHMtcmVhZC1pbi1odG1sUGFyc2VUcnlPckZpbmlzaC5w YXRjaCB8IDMxICsrKysrKysrKysrKysrKysrKysKPiAgcGF0Y2hlcy9saWJ4bWwyLTIuOS43L3Nl cmllcyAgICAgICAgICAgICAgICAgIHwgIDUgKy0tCj4gIDIgZmlsZXMgY2hhbmdlZCwgMzQgaW5z ZXJ0aW9ucygrKSwgMiBkZWxldGlvbnMoLSkKPiAgY3JlYXRlIG1vZGUgMTAwNjQ0IHBhdGNoZXMv bGlieG1sMi0yLjkuNy8wMDAxLU91dC1vZi1ib3VuZHMtcmVhZC1pbi1odG1sUGFyc2VUcnlPckZp bmlzaC5wYXRjaAo+IAo+IGRpZmYgLS1naXQgYS9wYXRjaGVzL2xpYnhtbDItMi45LjcvMDAwMS1P dXQtb2YtYm91bmRzLXJlYWQtaW4taHRtbFBhcnNlVHJ5T3JGaW5pc2gucGF0Y2ggYi9wYXRjaGVz L2xpYnhtbDItMi45LjcvMDAwMS1PdXQtb2YtYm91bmRzLXJlYWQtaW4taHRtbFBhcnNlVHJ5T3JG aW5pc2gucGF0Y2gKPiBuZXcgZmlsZSBtb2RlIDEwMDY0NAo+IGluZGV4IDAwMDAwMDAwMC4uYzIz Y2I0N2U1Cj4gLS0tIC9kZXYvbnVsbAo+ICsrKyBiL3BhdGNoZXMvbGlieG1sMi0yLjkuNy8wMDAx LU91dC1vZi1ib3VuZHMtcmVhZC1pbi1odG1sUGFyc2VUcnlPckZpbmlzaC5wYXRjaAo+IEBAIC0w LDAgKzEsMzEgQEAKPiArRnJvbTogTWFyY3VzIE1laXNzbmVyIDxtZWlzc25lckBzdXNlLmRlPgo+ ICtEYXRlOiBXZWQsIDMgSmFuIDIwMTggMTQ6NDM6NDEgKzAxMDAKPiArU3ViamVjdDogW1BBVENI XSBPdXQtb2YtYm91bmRzIHJlYWQgaW4gaHRtbFBhcnNlVHJ5T3JGaW5pc2gKPiArCj4gK09yaWdp bjogdmVuZG9yLCBodHRwczovL2J1Z3ppbGxhLm5vdmVsbC5jb20vYXR0YWNobWVudC5jZ2k/aWQ9 NzMyMzA5Cj4gK0J1ZzogaHR0cHM6Ly9idWd6aWxsYS5nbm9tZS5vcmcvc2hvd19idWcuY2dpP2lk PTc3NTIwMAo+ICtCdWctRGViaWFuOiBodHRwczovL2J1Z3MuZGViaWFuLm9yZy84NjI0NTAKPiAr QnVnLURlYmlhbi1TZWN1cml0eTogaHR0cHM6Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcv dHJhY2tlci9DVkUtMjAxNy04ODcyCj4gK0J1Zy1TVVNFOiBodHRwczovL2J1Z3ppbGxhLm5vdmVs bC5jb20vc2hvd19idWcuY2dpP2lkPTEwMzg0NDQKPiArRm9yd2FyZGVkOiB5ZXMsIGh0dHBzOi8v YnVnemlsbGEuZ25vbWUub3JnL2F0dGFjaG1lbnQuY2dpP2lkPTM2NjE5Mwo+ICtSZXZpZXdlZC1i eTogU2FsdmF0b3JlIEJvbmFjY29yc28gPGNhcm5pbEBkZWJpYW4ub3JnPgo+ICtMYXN0LVVwZGF0 ZTogMjAxOC0wMS0wMwo+ICstLS0KPiArIHBhcnNlci5jIHwgNCArKysrCj4gKyAxIGZpbGUgY2hh bmdlZCwgNCBpbnNlcnRpb25zKCspCj4gKwo+ICtkaWZmIC0tZ2l0IGEvcGFyc2VyLmMgYi9wYXJz ZXIuYwo+ICtpbmRleCAxYzVlMDM2ZWEyNjUuLjAyNTExMTA2N2FlOCAxMDA2NDQKPiArLS0tIGEv cGFyc2VyLmMKPiArKysrIGIvcGFyc2VyLmMKPiArQEAgLTEyNDY3LDYgKzEyNDY3LDEwIEBAIHht bEhhbHRQYXJzZXIoeG1sUGFyc2VyQ3R4dFB0ciBjdHh0KSB7Cj4gKyAJY3R4dC0+aW5wdXQtPmN1 ciA9IEJBRF9DQVNUIiI7Cj4gKyAJY3R4dC0+aW5wdXQtPmJhc2UgPSBjdHh0LT5pbnB1dC0+Y3Vy Owo+ICsgICAgICAgICBjdHh0LT5pbnB1dC0+ZW5kID0gY3R4dC0+aW5wdXQtPmN1cjsKPiArKyAg ICBpZiAoY3R4dC0+aW5wdXQtPmJ1ZikKPiArKyAgICAgICAgeG1sQnVmRW1wdHkgKGN0eHQtPmlu cHV0LT5idWYtPmJ1ZmZlcik7Cj4gKysgICAgZWxzZQo+ICsrICAgICAgICBjdHh0LT5pbnB1dC0+ bGVuZ3RoID0gMDsKPiArICAgICB9Cj4gKyB9Cj4gKyAKPiBkaWZmIC0tZ2l0IGEvcGF0Y2hlcy9s aWJ4bWwyLTIuOS43L3NlcmllcyBiL3BhdGNoZXMvbGlieG1sMi0yLjkuNy9zZXJpZXMKPiBpbmRl eCAwNWJhNWRkZWEuLmRjZjBkYmFmYyAxMDA2NDQKPiAtLS0gYS9wYXRjaGVzL2xpYnhtbDItMi45 Ljcvc2VyaWVzCj4gKysrIGIvcGF0Y2hlcy9saWJ4bWwyLTIuOS43L3Nlcmllcwo+IEBAIC0xLDYg KzEsNyBAQAo+ICAjIGdlbmVyYXRlZCBieSBnaXQtcHR4LXBhdGNoZXMKPiAtI3RhZzpiYXNlIC0t c3RhcnQtbnVtYmVyIDEKPiAgI3RhZzp1cHN0cmVhbSAtLXN0YXJ0LW51bWJlciAxCj4gICN0YWc6 cHR4IC0tc3RhcnQtbnVtYmVyIDIwMAo+ICAwMjAwLXhtbDItY29uZmlnLWlzLW5vdC1TWVNST09U LWF3YXJlLnBhdGNoCj4gLSMgYjY3MjBiZTk1NmQxYjQ2MTliYzFjMzQ3YTBjZWIxZGQgIC0gZ2l0 LXB0eC1wYXRjaGVzIG1hZ2ljCj4gKyN0YWc6YmFzZSAtLXN0YXJ0LW51bWJlciAxCj4gKzAwMDEt T3V0LW9mLWJvdW5kcy1yZWFkLWluLWh0bWxQYXJzZVRyeU9yRmluaXNoLnBhdGNoCgpUaGF0J3Mg YW4gdXBzdHJlYW0gcGF0Y2gsIHJpZ2h0PyBJdCBzaG91bGQgY29tZSBiZWZvcmUgdGhlIG90aGVy IHBhdGNoIGluCnRoZSAndXBzdHJlYW0nIHNlY3Rpb24uCgpNaWNoYWVsCgo+ICsjIDVhM2VkZTNl ODA4NTljYjdiYzVjNjMwYmM3ZGJlNDNjICAtIGdpdC1wdHgtcGF0Y2hlcyBtYWdpYwo+IC0tIAo+ IDIuMTcuMQo+IAo+IAo+IERpZWhsIEFLTyBTdGlmdHVuZyAmIENvLiBLRywgUGZhbm5lcnN0cmHD n2UgNzUtODMsIDg4MjM5IFdhbmdlbiBpbSBBbGxnw6R1Cj4gQmVyZWljaHN2b3JzdGFuZDogRGlw bC4tSW5nLiBNaWNoYWVsIFNpZWRlbnRvcCAoU3ByZWNoZXIpLCBKb3NlZiBGZWxsbmVyIChNaXRn bGllZCkKPiBTaXR6IGRlciBHZXNlbGxzY2hhZnQ6IFdhbmdlbiBpLkEuIOKAkyBSZWdpc3Rlcmdl cmljaHQ6IEFtdHNnZXJpY2h0IFVsbSBIUkEgNjIwNjA5IOKAkyBQZXJzw7ZubGljaCBoYWZ0ZW5k ZSBHZXNlbGxzY2hhZnRlcmluOiBEaWVobCBWZXJ3YWx0dW5ncy1TdGlmdHVuZyDigJMgU2l0ejog TsO8cm5iZXJnIOKAkyBSZWdpc3RlcmdlcmljaHQ6IEFtdHNnZXJpY2h0IE7DvHJuYmVyZyBIUkEg MTE3NTYg4oCTCj4gVm9yc3RhbmQ6IERyLi1JbmcuIEthcmwgVHJhZ2wgKFZvcnNpdHplbmRlciks IEhlcnIgRGlwbC4tV2lydHNjaC4tSW5nLiBXb2xmZ2FuZyBXZWdnZW4gKHN0ZWxsdmVydHJldGVu ZGVyIFZvcnNpdHplbmRlciksIERpcGwuLUtmbS4gQ2xhdXMgR8O8bnRoZXIsIERpcGwuLUtmbS4g RnJhbmsgR3V0emVpdCwgRHIuLUluZy4gSGVpbnJpY2ggU2NodW5rLCBEci4tSW5nLiBNaWNoYWVs IFNpZWRlbnRvcCAsIERpcGwuLUtmbS4gRHIuLUluZy4gTWFydGluIFNvbW1lciwgRGlwbC4tSW5n LiAoRkgpIFJhaW5lciB2b24gQm9yc3RlbCwgVm9yc2l0emVuZGVyIGRlcyBBdWZzaWNodHNyYXRl czogRHIuIEtsYXVzIE1haWVyCj4gX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f X19fX19fCj4gRGVyIEluaGFsdCBkZXIgdm9yc3RlaGVuZGVuIEUtTWFpbCBpc3QgbmljaHQgcmVj aHRsaWNoIGJpbmRlbmQuIERpZXNlIEUtTWFpbCBlbnRoYWVsdCB2ZXJ0cmF1bGljaGUgdW5kL29k ZXIgcmVjaHRsaWNoIGdlc2NodWV0enRlIEluZm9ybWF0aW9uZW4uCj4gSW5mb3JtaWVyZW4gU2ll IHVucyBiaXR0ZSwgd2VubiBTaWUgZGllc2UgRS1NYWlsIGZhZWxzY2hsaWNoZXJ3ZWlzZSBlcmhh bHRlbiBoYWJlbi4gQml0dGUgbG9lc2NoZW4gU2llIGluIGRpZXNlbSBGYWxsIGRpZSBOYWNocmlj aHQuIEplZGUgdW5lcmxhdWJ0ZSBGb3JtIGRlciBSZXByb2R1a3Rpb24sIEJla2FubnRnYWJlLCBB ZW5kZXJ1bmcsIFZlcnRlaWx1bmcgdW5kL29kZXIgUHVibGlrYXRpb24gZGllc2VyIEUtTWFpbCBp c3Qgc3RyZW5nc3RlbnMgdW50ZXJzYWd0Lgo+IFRoZSBjb250ZW50cyBvZiB0aGUgYWJvdmUgbWVu dGlvbmVkIGUtbWFpbCBpcyBub3QgbGVnYWxseSBiaW5kaW5nLiBUaGlzIGUtbWFpbCBjb250YWlu cyBjb25maWRlbnRpYWwgYW5kL29yIGxlZ2FsbHkgcHJvdGVjdGVkIGluZm9ybWF0aW9uLiBQbGVh c2UgaW5mb3JtIHVzIGlmIHlvdSBoYXZlIHJlY2VpdmVkIHRoaXMgZS1tYWlsIGJ5IG1pc3Rha2Ug YW5kIGRlbGV0ZSBpdCBpbiBzdWNoIGEgY2FzZS4gRWFjaCB1bmF1dGhvcml6ZWQgcmVwcm9kdWN0 aW9uLCBkaXNjbG9zdXJlLCBhbHRlcmF0aW9uLCBkaXN0cmlidXRpb24gYW5kL29yIHB1YmxpY2F0 aW9uIG9mIHRoaXMgZS1tYWlsIGlzIHN0cmljdGx5IHByb2hpYml0ZWQuCj4gCj4gX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KPiBwdHhkaXN0IG1haWxpbmcg bGlzdAo+IHB0eGRpc3RAcGVuZ3V0cm9uaXguZGUKCi0tIApQZW5ndXRyb25peCBlLksuICAgICAg ICAgICAgICAgICAgICAgICAgICAgfCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgfApJbmR1 c3RyaWFsIExpbnV4IFNvbHV0aW9ucyAgICAgICAgICAgICAgICAgfCBodHRwOi8vd3d3LnBlbmd1 dHJvbml4LmRlLyAgfApQZWluZXIgU3RyLiA2LTgsIDMxMTM3IEhpbGRlc2hlaW0sIEdlcm1hbnkg fCBQaG9uZTogKzQ5LTUxMjEtMjA2OTE3LTAgICAgfApBbXRzZ2VyaWNodCBIaWxkZXNoZWltLCBI UkEgMjY4NiAgICAgICAgICAgfCBGYXg6ICAgKzQ5LTUxMjEtMjA2OTE3LTU1NTUgfAoKX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcHR4ZGlzdCBtYWlsaW5n IGxpc3QKcHR4ZGlzdEBwZW5ndXRyb25peC5kZQ==