Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:2154-1

Опубликовано: 25 авг. 2016
Источник: suse-cvrf

Описание

Security update for xerces-c

xerces-c was updated to fix one security issue.

This security issue was fixed:

  • CVE-2016-2099: Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ did not properly handle exceptions raised in the XMLReader class, which allowed context-dependent attackers to have unspecified impact via an invalid character in an XML document (bsc#979208).
  • CVE-2016-4463: Apache Xerces-C XML Parser crashed on malformed DTD (bnc#985860).

Список пакетов

SUSE Linux Enterprise Desktop 12 SP1
libxerces-c-3_1-3.1.1-12.3
libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1
libxerces-c-3_1-3.1.1-12.3
libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Server for SAP Applications 12 SP1
libxerces-c-3_1-3.1.1-12.3
libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Software Development Kit 12 SP1
libxerces-c-devel-3.1.1-12.3

Описание

Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML document.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libxerces-c-3_1-3.1.1-12.3
SUSE Linux Enterprise Desktop 12 SP1:libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1:libxerces-c-3_1-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1:libxerces-c-3_1-32bit-3.1.1-12.3

Ссылки

Описание

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libxerces-c-3_1-3.1.1-12.3
SUSE Linux Enterprise Desktop 12 SP1:libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1:libxerces-c-3_1-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1:libxerces-c-3_1-32bit-3.1.1-12.3

Ссылки
Уязвимость SUSE-SU-2016:2154-1