- 
    Tue Mar 15 2022 Tomas Korbar <tkorbar@redhat.com> - 2.2.5-4.3
    
- Improve fix for CVE-2022-25236
- Related: CVE-2022-25236
   
  
  - 
    Mon Mar 07 2022 Tomas Korbar <tkorbar@redhat.com> - 2.2.5-4.2
    
- Fix multiple CVEs
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
   
  
  - 
    Wed Feb 16 2022 Tomas Korbar <tkorbar@redhat.com> - 2.2.5-4.1
    
- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
   
  
  - 
    Fri Apr 24 2020 Joe Orton <jorton@redhat.com> - 2.2.5-4
    
- add security fixes for CVE-2018-20843, CVE-2019-15903
   
  
  - 
    Wed Feb 07 2018 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.5-3
    
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
   
  
  - 
    Sat Feb 03 2018 Igor Gnatenko <ignatenkobrain@fedoraproject.org> - 2.2.5-2
    
- Switch to %ldconfig_scriptlets
   
  
  - 
    Thu Nov 02 2017 Joe Orton <jorton@redhat.com> - 2.2.5-1
    
- update to 2.2.5 (#1508667)
   
  
  - 
    Mon Aug 21 2017 Joe Orton <jorton@redhat.com> - 2.2.4-1
    
- update to 2.2.4 (#1483359)
   
  
  - 
    Fri Aug 04 2017 Joe Orton <jorton@redhat.com> - 2.2.3-1
    
- fix tests with unsigned char (upstream PR 109)
- update to 2.2.3 (#1473266)
   
  
  - 
    Wed Aug 02 2017 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.2-4
    
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild