Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian 8 DSA-3579-1: Critical Use-After-Free in Xerces-C Library

debian
Calendar Grey May 16, 2016
Debian Logo
The latest Debian security patch DSA-3580-1 resolves a severe buffer overflow vulnerability in libxml2 library. Ensure you update promptly!
Gustavo Grieco discovered an use-after-free vulnerability in xerces-c, a validating XML parser library for C++, due to not properly handling invalid characters in XML input documen...

Summary

For the stable distribution (jessie), this problem has been fixed in
version 3.1.1-5.1+deb8u2.

For the testing distribution (stretch), this problem has been fixed
in version 3.1.3+debian-2.

For the unstable distribution (sid), this problem has been fixed in
version 3.1.3+debian-2.

We recommend that you upgrade your xerces-c packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: xerces-c
CVE ID: CVE-2016-2099

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here