MGASA-2018-0381 - Updated xml-security-c packages fix security vulnerability

Publication date: 21 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0381.html
Type: security
Affected Mageia releases: 6

It was discovered that the Apache XML Security for C++ library performed
insufficient validation of KeyInfo hints, which could result in denial of
service via NULL pointer dereferences when processing malformed XML data.

References:
- https://bugs.mageia.org/show_bug.cgi?id=23401
- https://issues.apache.org/jira/projects/SANTUARIO/issues/SANTUARIO-491

SRPMS:
- 6/core/xml-security-c-1.7.3-2.1.mga6

Mageia 2018-0381: xml-security-c security update

It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer derefere...

Summary

It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data. References:

References

- https://bugs.mageia.org/show_bug.cgi?id=23401

- https://issues.apache.org/jira/projects/SANTUARIO/issues/SANTUARIO-491

Resolution

MGASA-2018-0381 - Updated xml-security-c packages fix security vulnerability

SRPMS

- 6/core/xml-security-c-1.7.3-2.1.mga6

Severity
Publication date: 21 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0381.html
Type: security

Related News