_______________________________________________________________________
Package : kompozer
Date : August 24, 2009
Affected: 2009.0, 2009.1
_______________________________________________________________________
Problem Description:
A vulnerability was found in xmltok_impl.c (expat) that with
specially crafted XML could be exploited and lead to a denial of
service attack. Related to CVE-2009-2625.
Additionally on 2009.0 a patch was added to prevent kompozer from
crashing (#44830), on 2009.1 a format string patch was added to make
it build with the -Wformat -Werror=format-security gcc optimization
switch added in 2009.1
This update fixes these issues.
_______________________________________________________________________
References:
https://bugs.gentoo.org/show_bug.cgi?id=280615
_______________________________________________________________________