UbuntuUpdates.org

Package "libxml-parser-perl"

Name: libxml-parser-perl

Description:

Perl module for parsing XML files

Latest version: 2.46-3ubuntu0.1
Release: jammy (22.04)
Level: updates
Repository: main
Homepage: https://metacpan.org/release/XML-Parser

Links


Download "libxml-parser-perl"


Other versions of "libxml-parser-perl" in Jammy

Repository Area Version
base main 2.46-3build1
security main 2.46-3ubuntu0.1

Changelog

Version: 2.46-3ubuntu0.1 2026-04-14 12:08:06 UTC

  libxml-parser-perl (2.46-3ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: heap corruption in parse_stream()
    - debian/patches/CVE-2006-10002.patch: fix buffer overflow in
      parse_stream when filehandle has :utf8 layer in Expat/Expat.xs,
      t/utf8_stream.t.
    - CVE-2006-10002
  * SECURITY UPDATE: off-by-one heap buffer overflow in st_serial_stack
    - debian/patches/CVE-2006-10003.patch: fix off-by-one heap buffer
      overflow in st_serial_stack growth check in Expat/Expat.xs,
      t/deep_nesting.t.
    - CVE-2006-10003

 -- Marc Deslauriers <email address hidden> Fri, 10 Apr 2026 11:24:01 -0400

CVE-2006-10002 XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crash
CVE-2006-10003 XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the s



About   -   Send Feedback to @ubuntu_updates