From ${URL} : Fix NULL pointer deref in XPointer range-to - Check for errors after evaluating first operand. - Add sanity check for empty stack. Found with afl-fuzz. @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Patch is not present in latest 2.9.4 release.
Security bump to -r1 in coordination with leio. @maintainer(s), please let us know when you are ready to stabilize. https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=060503be258912e25b6da77ca79d450553ed0be3
amd64 stable
x86 stable
Stable on alpha.
arm stable
Stable for PPC64.
sparc stable
Stable for HPPA.
ia64/ppc bump
ppc stable
This issue was resolved and addressed in GLSA 201701-37 at https://security.gentoo.org/glsa/201701-37 by GLSA coordinator Thomas Deutschmann (whissi).
Re-opening for remaining arch.
ia64 stable. Maintainer(s), please cleanup.
cleanup done to the extent possible with arm64, m68k, s390 and sh still there.
All done.