Описание
Security update for xerces-c
xerces-c was updated to fix one security issue.
This security issue was fixed:
- CVE-2016-2099: Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ did not properly handle exceptions raised in the XMLReader class, which allowed context-dependent attackers to have unspecified impact via an invalid character in an XML document (bsc#979208).
- CVE-2016-4463: Apache Xerces-C XML Parser crashed on malformed DTD (bnc#985860).
This update was imported from the SUSE:SLE-12:Update update project.
Список пакетов
openSUSE Leap 42.1
libxerces-c-3_1-3.1.1-19.1
libxerces-c-3_1-32bit-3.1.1-19.1
libxerces-c-devel-3.1.1-19.1
xerces-c-3.1.1-19.1
Ссылки
- E-Mail link for openSUSE-SU-2016:2232-1
- SUSE Security Ratings
Описание
Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML document.
Затронутые продукты
openSUSE Leap 42.1:libxerces-c-3_1-3.1.1-19.1
openSUSE Leap 42.1:libxerces-c-3_1-32bit-3.1.1-19.1
openSUSE Leap 42.1:libxerces-c-devel-3.1.1-19.1
openSUSE Leap 42.1:xerces-c-3.1.1-19.1
Ссылки
- CVE-2016-2099
- SUSE Bug 979208
Описание
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
Затронутые продукты
openSUSE Leap 42.1:libxerces-c-3_1-3.1.1-19.1
openSUSE Leap 42.1:libxerces-c-3_1-32bit-3.1.1-19.1
openSUSE Leap 42.1:libxerces-c-devel-3.1.1-19.1
openSUSE Leap 42.1:xerces-c-3.1.1-19.1
Ссылки
- CVE-2016-4463
- SUSE Bug 985860