Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:2232-1

Опубликовано: 04 сент. 2016
Источник: suse-cvrf

Описание

Security update for xerces-c

xerces-c was updated to fix one security issue.

This security issue was fixed:

  • CVE-2016-2099: Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ did not properly handle exceptions raised in the XMLReader class, which allowed context-dependent attackers to have unspecified impact via an invalid character in an XML document (bsc#979208).
  • CVE-2016-4463: Apache Xerces-C XML Parser crashed on malformed DTD (bnc#985860).

This update was imported from the SUSE:SLE-12:Update update project.

Список пакетов

openSUSE Leap 42.1
libxerces-c-3_1-3.1.1-19.1
libxerces-c-3_1-32bit-3.1.1-19.1
libxerces-c-devel-3.1.1-19.1
xerces-c-3.1.1-19.1

Описание

Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML document.


Затронутые продукты
openSUSE Leap 42.1:libxerces-c-3_1-3.1.1-19.1
openSUSE Leap 42.1:libxerces-c-3_1-32bit-3.1.1-19.1
openSUSE Leap 42.1:libxerces-c-devel-3.1.1-19.1
openSUSE Leap 42.1:xerces-c-3.1.1-19.1

Ссылки

Описание

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.


Затронутые продукты
openSUSE Leap 42.1:libxerces-c-3_1-3.1.1-19.1
openSUSE Leap 42.1:libxerces-c-3_1-32bit-3.1.1-19.1
openSUSE Leap 42.1:libxerces-c-devel-3.1.1-19.1
openSUSE Leap 42.1:xerces-c-3.1.1-19.1

Ссылки