Publishing details

Changelog

xerces-c (3.1.1-5.1+deb8u4build0.14.04.1) trusty-security; urgency=medium

  * fake sync from Debian

xerces-c (3.1.1-5.1+deb8u4) jessie; urgency=medium

  * Fix CVE-2017-12627: Alberto Garcia, Francisco Oca and Suleman Ali of
    Offensive Research discovered that the Xerces-C XML parser mishandles
    certain kinds of external DTD references, resulting in dereference of a
    NULL pointer while processing the path to the DTD. The bug allows for a
    denial of service attack in applications that allow DTD processing and do
    not prevent external DTD usage, and could conceivably result in remote code
    execution.

 -- Mike Salvatore <email address hidden>  Thu, 06 Dec 2018 11:09:03 -0500

Available diffs

Builds

Built packages

Package files