[ubuntu/trusty-updates] xerces-c 3.1.1-5.1+deb8u4build0.14.04.1 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Thu Dec 6 17:58:08 UTC 2018


xerces-c (3.1.1-5.1+deb8u4build0.14.04.1) trusty-security; urgency=medium

  * fake sync from Debian

xerces-c (3.1.1-5.1+deb8u4) jessie; urgency=medium

  * Fix CVE-2017-12627: Alberto Garcia, Francisco Oca and Suleman Ali of
    Offensive Research discovered that the Xerces-C XML parser mishandles
    certain kinds of external DTD references, resulting in dereference of a
    NULL pointer while processing the path to the DTD. The bug allows for a
    denial of service attack in applications that allow DTD processing and do
    not prevent external DTD usage, and could conceivably result in remote code
    execution.

Date: 2018-12-06 16:12:12.805745+00:00
Changed-By: Mike Salvatore <mike.salvatore at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/xerces-c/3.1.1-5.1+deb8u4build0.14.04.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Trusty-changes mailing list