Changelog for
expat-debuginfo-2.1.0-17.9.x86_64.rpm :
* Tue May 17 2016 kstreitovaAATTsuse.com- add expat-2.1.0-heap_buffer_overflow.patch to fix multiple integer overflows [bnc#980391], [CVE-2015-1283]- fix some issues with the current version of the expat-2.1.0-parser_crashes_on_malformed_input.patch [bnc#979441], [CVE-2016-0718]
* Wed May 11 2016 kstreitovaAATTsuse.com- add expat-2.1.0-parser_crashes_on_malformed_input.patch to fix Expat XML parser that mishandles certain kinds of malformed input documents [bnc#979441], [CVE-2016-0718]
* Tue Mar 26 2013 mmeisterAATTsuse.com- Added url as source. Please see http://en.opensuse.org/SourceUrls
* Thu Feb 21 2013 jengelhAATTinai.de- Sanitize description of expat (replace it with a more current one from the homepage)
* Mon Feb 04 2013 schwabAATTsuse.de- Update config.guess/sub for aarch64
* Wed Jan 23 2013 pgajdosAATTsuse.com- fix of fix of [bnc#798644]- according to upstream changelog: - Improved ability to build without the configure-generated expat_config.h header. This is useful for applications which embed Expat rather than linking in the library. because I am not exactly sure about implication of this, rather use - DXML_HAVE_VISIBILITY in CFLAG_VISIBILITY in expat-visibility.patch
* Tue Jan 22 2013 jengelhAATTinai.de- Executing autoreconf requires autoconf BuildRequire
* Fri Jan 18 2013 pgajdosAATTsuse.com- really hide private Xml
* symbols [bnc#798644]
* modified visibility.patch
* Tue Apr 10 2012 tabrahamAATTnovell.com- update to 2.1.0 - Bug Fixes: [#1742315]: Harmful XML_ParserCreateNS suggestion. [#2895533]: CVE-2012-1147 - Resource leak in readfilemap.c. [#1785430]: Expat build fails on linux-amd64 with gcc version>=4.1 -O3. [#1983953], 2517952, 2517962, 2649838: Build modifications using autoreconf instead of buildconf.sh. [#2815947], #2884086: OBJEXT and EXEEXT support while building. [#1990430]: CVE-2009-3720 - Parser crash with special UTF-8 sequences. [#2517938]: xmlwf should return non-zero exit status if not well-formed. [#2517946]: Wrong statement about XMLDecl in xmlwf.1 and xmlwf.sgml. [#2855609]: Dangling positionPtr after error. [#2894085]: CVE-2009-3560 - Buffer over-read and crash in big2_toUtf8(). [#2958794]: CVE-2012-1148 - Memory leak in poolGrow. [#2990652]: CMake support. [#3010819]: UNEXPECTED_STATE with a trailing \"%\" in entity value. [#3206497]: Unitialized memory returned from XML_Parse. [#3287849]: make check fails on mingw-w64. [#3496608]: CVE-2012-0876 - Hash DOS attack. - Patches: [#1749198]: pkg-config support. [#3010222]: Fix for bug #3010819. [#3312568]: CMake support. [#3446384]: Report byte offsets for attr names and values. - New Features / API changes:
* Added new API member XML_SetHashSalt() that allows setting an intial value (salt) for hash calculations. This is part of the fix for bug #3496608 to randomize hash parameters.
* When compiled with XML_ATTR_INFO defined, adds new API member XML_GetAttributeInfo() that allows retrieving the byte offsets for attribute names and values (patch #3446384).
* Added CMake build system. See bug #2990652 and patch #3312568.
* Added run-benchmark target to Makefile.in - relies on testdata module present in the same relative location as in the repository.
* Tue Mar 06 2012 tabrahamAATTnovell.com- update to 2.1.0 beta
* refreshed expat-visibility.patch
* removed obsolete expat-CVE-2009-3560.patch
* removed obsolete expat-CVE-2009-2625.patch - hash table DOS attack fix - accumulated bug fixes and some changes to the build system - new conditional feature to make byte offsets for attributes and attribute names available
* Sun Feb 12 2012 crrodriguezAATTopensuse.org- Put libraries back to %{_libdir}, /usr merge project
* Fri Dec 02 2011 cooloAATTsuse.com- add automake as buildrequire to avoid implicit dependency
* Sun Oct 30 2011 crrodriguezAATTopensuse.org- Hide non public symbols reusing existing win32 API export/imports- annotate malloc/realloc-like functions with attribute alloc_size to catch possible misuses in calling code.
* Sun Sep 18 2011 jengelhAATTmedozas.de- Remove redundant/obsolete tags/sections from specfile (cf. packaging guidelines)- Use %_smp_mflags for parallel build- Add libexpat-devel to baselibs
* Fri Feb 25 2011 prusnakAATTopensuse.org- fix license (MIT) in spec file
* Fri Jan 08 2010 prusnakAATTsuse.cz- fix CVE-2009-3560.patch [bnc#566434]
* Sun Dec 13 2009 jengelhAATTmedozas.de- add baselibs.conf as a source
* Fri Dec 04 2009 prusnakAATTsuse.cz- fix DoS (CVE-2009-3560.patch) [bnc#558892]
* Thu Oct 29 2009 prusnakAATTsuse.cz- fix DoS (CVE-2009-2625.patch) [bnc#550664]
* Sun Apr 05 2009 crrodriguezAATTsuse.de- test suite requires gcc-c++ to compile
* Thu Feb 19 2009 crrodriguezAATTsuse.de- remove static libraries, shouldnt be needed anymore.- run make check
* Wed Dec 10 2008 olhAATTsuse.de- use Obsoletes: -XXbit only for ppc64 to help solver during distupgrade (bnc#437293)
* Thu Oct 30 2008 olhAATTsuse.de- obsolete old -XXbit packages (bnc#437293)
* Thu Apr 10 2008 roAATTsuse.de- added baselibs.conf file to build xxbit packages for multilib support
* Sat Jul 28 2007 cooloAATTsuse.de- fix devel symlink
* Wed Jul 25 2007 prusnakAATTsuse.cz- move libraries from /usr/lib to /lib [#285472]- replace deprecated %run_ldconfig with /sbin/ldconfig
* Thu Jun 07 2007 prusnakAATTsuse.cz- update to 2.0.1: ( from Changes )
* Fixed bugs #1515266, 1515600: The character data handler\'s calling of XML_StopParser() was not handled properly; if the parser was stopped and the handler set to NULL, the parser would segfault.
* Fixed bug #1690883: Expat failed on EBCDIC systems as it assumed some character constants to be ASCII encoded.
* Minor cleanups of the test harness.
* Fixed xmlwf bug #1513566: \"out of memory\" error on file size zero.
* Fixed outline.c bug #1543233: missing a final XML_ParserFree() call.
* Fixes and improvements for Windows platform: bugs #1409451, #1476160, 1548182, 1602769, 1717322.
* Build fixes for various platforms: HP-UX, Tru64, Solaris 9: patch #1437840, bug #1196180. All Unix: #1554618 (refreshed config.sub/config.guess). [#1490371], #1613457: support both, DESTDIR and INSTALL_ROOT, without relying on GNU-Make specific features. [#1647805]: Patched configure.in to work better with Intel compiler.
* Fixes to Makefile.in to have make check work correctly: bugs #1408143, #1535603, #1536684.
* Added Open Watcom support: patch #1523242.
* Tue Apr 17 2007 prusnakAATTsuse.cz- split libexpat1 and libexpat-devel subpackages [#260214]
* Thu Oct 19 2006 dmuellerAATTsuse.de- strip .la file
* Wed Jan 25 2006 mlsAATTsuse.de- converted neededforbuild to BuildRequires
* Thu Jan 12 2006 roAATTsuse.de- fixed file list for debuginfo package (do not pack all of libdir)
* Wed Jan 11 2006 mjancarAATTsuse.cz- update to 2.0.0
* Mon Jan 09 2006 mjancarAATTsuse.cz- update to 2.0 pre release
* Wed Nov 10 2004 roAATTsuse.de- fixed filelist
* Mon Aug 09 2004 tcrhakAATTsuse.cz- update to 1.95.8
* Thu Feb 05 2004 kukukAATTsuse.de- Build as user
* Thu Feb 05 2004 tcrhakAATTsuse.cz- update to version 1.95.7
* Tue Feb 18 2003 tcrhakAATTsuse.cz- in expat.h, declare enum XML_Status before using it; put into patch \"...-header.diff\" [bug #23742]
* Mon Feb 17 2003 tcrhakAATTsuse.cz- updated to version 1.95.6
* Sun Dec 22 2002 tcrhakAATTsuse.cz- update to version 1.95.5
* Sat Jul 13 2002 tcrhakAATTsuse.cz- update to version 1.95.4
* Thu Mar 28 2002 tcrhakAATTsuse.cz- added parameter --target to configure
* Mon Jan 14 2002 rvasiceAATTsuse.cz- use %{_libdir} and %{_lib}
* Tue Nov 20 2001 rvasiceAATTsuse.cz- fix URL in spec file
* Wed Aug 15 2001 rvasiceAATTsuse.cz- update to version 1.95.2- spec file cleanup- added DESTDIR
* Mon May 14 2001 pblahaAATTsuse.cz- fixed links for soname of libexpat.so
*
* Fri May 11 2001 cihlarAATTsuse.cz- fixed soname of libexpat.so.1.2
* Fri Jan 05 2001 pblahaAATTsuse.cz- back on stable version 1.2 added build shared libexpat.so
* Thu Jan 04 2001 pblahaAATTsuse.cz- update on 1.95.1 on sourgeforge needed for midgard- new description
* Thu Mar 09 2000 keAATTsuse.de- Don\'t \"install\" symlinks; use \"cp\"; reported by bs; proposed fix by ro.- Cleanup the spec file: better Group tag; more accurate files list.
* Tue Nov 23 1999 keAATTsuse.de- first SuSE package: version 1.1.- apply Debian patch to build shared libs.- build libexpat.a.