Subject: CVS commit: pkgsrc/textproc/libxml2
From: Matthias Drochner
Date: 2012-03-09 13:12:28
Message id: 20120309121228.5E2FE175DD@cvs.netbsd.org

Log Message:
Add patch from upstream to add hash randomization.
Without that, (untrusted) input can fill hash buckets uneven, causing
high CPU load. (CVE-2012-0841)
To get a patch which is simple enough to get pulled up to the stable
pkgsrc branch, I've not touched "configure" but just assumed that
the POSIX functions rand(), srand() and time() are present.
bump PKGREV

Files:
RevisionActionfile
1.114modifypkgsrc/textproc/libxml2/Makefile
1.89modifypkgsrc/textproc/libxml2/distinfo
1.1addpkgsrc/textproc/libxml2/patches/patch-CVE-2012-0841-aa
1.1addpkgsrc/textproc/libxml2/patches/patch-CVE-2012-0841-ab
1.1addpkgsrc/textproc/libxml2/patches/patch-CVE-2012-0841-ac