Debian Security Update DSA-4814 xerces-c - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,915
Reaction score
75
Credits
-1,257
It was discovered that xerces-c, a validating XML parser library for C++, did not correctly scan DTDs. The use-after-free vulnerability resulting from this issue would allow a remote attacker to leverage a specially crafted XML file in order to crash the application or potentially execute arbitrary code. Please note that the patch fixing this issue comes at the expense of a newly introduced memory leak.

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top