Описание
Security update for xerces-c
xerces-c was updated to fix one security issue.
This security issue was fixed:
- CVE-2016-2099: Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ did not properly handle exceptions raised in the XMLReader class, which allowed context-dependent attackers to have unspecified impact via an invalid character in an XML document (bsc#979208).
- CVE-2016-4463: Apache Xerces-C XML Parser crashed on malformed DTD (bnc#985860).
Список пакетов
SUSE Linux Enterprise Desktop 12 SP1
libxerces-c-3_1-3.1.1-12.3
libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1
libxerces-c-3_1-3.1.1-12.3
libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Server for SAP Applications 12 SP1
libxerces-c-3_1-3.1.1-12.3
libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Software Development Kit 12 SP1
libxerces-c-devel-3.1.1-12.3
Ссылки
- Link for SUSE-SU-2016:2154-1
- E-Mail link for SUSE-SU-2016:2154-1
- SUSE Security Ratings
- SUSE Bug 979208
- SUSE Bug 985860
- SUSE CVE CVE-2016-2099 page
- SUSE CVE CVE-2016-4463 page
Описание
Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML document.
Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libxerces-c-3_1-3.1.1-12.3
SUSE Linux Enterprise Desktop 12 SP1:libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1:libxerces-c-3_1-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1:libxerces-c-3_1-32bit-3.1.1-12.3
Ссылки
- CVE-2016-2099
- SUSE Bug 979208
Описание
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libxerces-c-3_1-3.1.1-12.3
SUSE Linux Enterprise Desktop 12 SP1:libxerces-c-3_1-32bit-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1:libxerces-c-3_1-3.1.1-12.3
SUSE Linux Enterprise Server 12 SP1:libxerces-c-3_1-32bit-3.1.1-12.3
Ссылки
- CVE-2016-4463
- SUSE Bug 985860