xml_parse_setup() does not disable XML entity expansion, technically introducing a denial-of-service issue ("billion laughs attack"). I say "technically" because the file is trusted and its signature is verified before parsing. But given that it was downloaded from the network, fixing this is still a good idea. Adding the following handler using XML_SetEntityDeclHandler(parser, EntityDeclHandler); should be sufficient to address this issue. // Stop the parser when an entity declaration is encountered. static void EntityDeclHandler(void *userData, const XML_Char *entityName, int is_parameter_entity, const XML_Char *value, int value_length, const XML_Char *base, const XML_Char *systemId, const XML_Char *publicId, const XML_Char *notationName) { XML_StopParser((XML_Parser)userData, XML_FALSE); }
unbound-1.4.19-1.fc18 has been submitted as an update for Fedora 18. https://admin.fedoraproject.org/updates/unbound-1.4.19-1.fc18
unbound-1.4.19-1.fc17 has been submitted as an update for Fedora 17. https://admin.fedoraproject.org/updates/unbound-1.4.19-1.fc17
unbound-1.4.19-1.el6 has been submitted as an update for Fedora EPEL 6. https://admin.fedoraproject.org/updates/unbound-1.4.19-1.el6
Package unbound-1.4.19-1.fc18: * should fix your issue, * was pushed to the Fedora 18 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing unbound-1.4.19-1.fc18' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2012-20836/unbound-1.4.19-1.fc18 then log in and leave karma (feedback).
unbound-1.4.19-1.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
unbound-1.4.19-1.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
unbound-1.4.19-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
unbound-1.4.20-6.fc19 has been submitted as an update for Fedora 19. https://admin.fedoraproject.org/updates/unbound-1.4.20-6.fc19
unbound-1.4.20-1.fc18 has been submitted as an update for Fedora 18. https://admin.fedoraproject.org/updates/unbound-1.4.20-1.fc18
unbound-1.4.20-7.fc19 has been submitted as an update for Fedora 19. https://admin.fedoraproject.org/updates/unbound-1.4.20-7.fc19
unbound-1.4.20-3.fc18 has been submitted as an update for Fedora 18. https://admin.fedoraproject.org/updates/unbound-1.4.20-3.fc18
unbound-1.4.20-3.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.