xml-security-c 1.6.1-5+deb7u1~bpo60+1

Date: Tue, 18 Jun 2013 10:39:10 -0700
Source: xml-security-c
Version: 1.6.1-5+deb7u1~bpo60+1
Maintainer: Debian Shib Team <pkg-shibboleth-devel@lists.alioth.debian.org>
Changed-By: Russ Allbery <rra@debian.org>
 libxml-security-c-dev - C++ library for XML Digital Signatures (development)
 libxml-security-c16 - C++ library for XML Digital Signatures (runtime)
Closes: 656658
 xml-security-c (1.6.1-5+deb7u1~bpo60+1) squeeze-backports; urgency=high
   * Backport to oldstable.
   * Revert the change to use multiarch and force a non-multiarch libdir.
   * Relax versioned dependency on libssl-dev to build on squeeze.
 xml-security-c (1.6.1-5+deb7u1) stable-security; urgency=high
   * Apply upstream patch to fix a spoofing vulnerability that allows an
     attacker to reuse existing signatures with arbitrary content.
   * Apply upstream patch to fix a stack overflow in the processing of
     malformed XPointer expressions in the XML Signature Reference
     processing code.  (CVE-2013-2154)
   * Apply upstream patch to fix processing of the output length of an
     HMAC-based XML Signature that could cause a denial of service when
     processing specially chosen input.  (CVE-2013-2155)
   * Apply upstream patch to fix a heap overflow in the processing of the
     PrefixList attribute optionally used in conjunction with Exclusive
     Canonicalization, potentially allowing arbitrary code execution.
 xml-security-c (1.6.1-5) unstable; urgency=low
   * Revert changes to add symbols file.  Due to churn in weak symbols for
     inlined functions, it doesn't appear maintainanable with existing
     tools, and for this library the shlibs behavior seems sufficient.
   * Minor update to the format of the debian/copyright file.
 xml-security-c (1.6.1-4) unstable; urgency=low
   * Update symbols files for all non-i386 architectures currently built by
     the buildds except mipsel (which will hopefully be the same as mips).
   * Build-Depend on pkg-kde-tools and use its symbolhelper plugin so that
     the package can use the output of pkgkde-symbolshelper.
 xml-security-c (1.6.1-3) unstable; urgency=low
   * Also enable bindnow hardening build flags and use the correct syntax
     to add additional hardening flags.
   * Add symbols file constructed with pkgkde-symbolshelper.  Add a
     README.source file with a pointer to the documentation.
 xml-security-c (1.6.1-2) unstable; urgency=low
   * Update to debhelper compatibility level V9.
     - Enable hardening build flags.  (Closes: #656658)
     - Enable multiarch support.
