pkgsrc/textproc/expat/patches/patch-ab
drochner 501fb8a6d8 add patch from upstream CVS to fix CVE-2009-3560
(possible DOS due to crash on bad input)
bump PKGREVISION
2010-01-26 18:37:01 +00:00

16 lines
483 B
Text

$NetBSD: patch-ab,v 1.1 2010/01/26 18:37:01 drochner Exp $
CVE-2009-3560
--- lib/xmlparse.c.orig 2007-05-08 02:25:35.000000000 +0000
+++ lib/xmlparse.c
@@ -3703,6 +3703,9 @@ doProlog(XML_Parser parser,
return XML_ERROR_UNCLOSED_TOKEN;
case XML_TOK_PARTIAL_CHAR:
return XML_ERROR_PARTIAL_CHAR;
+ case -XML_TOK_PROLOG_S:
+ tok = -tok;
+ break;
case XML_TOK_NONE:
#ifdef XML_DTD
/* for internal PE NOT referenced between declarations */