Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1177-1

Опубликовано: 10 авг. 2020
Источник: suse-cvrf

Описание

Security update for perl-XML-Twig

This update for perl-XML-Twig fixes the following issues:

  • Security fix [bsc#1008644, CVE-2016-9180]
    • Setting expand_external_ents to 0 or -1 currently doesn't work as expected; To completely turn off expanding external entities use no_xxe.
    • Update documentation for XML::Twig to mention problems with expand_external_ents and add information about new no_xxe argument

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.1
perl-XML-Twig-3.52-lp151.3.3.1

Описание

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.


Затронутые продукты
openSUSE Leap 15.1:perl-XML-Twig-3.52-lp151.3.3.1

Ссылки