It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data. References:
- https://bugs.mageia.org/show_bug.cgi?id=23401
- https://issues.apache.org/jira/projects/SANTUARIO/issues/SANTUARIO-491
- 6/core/xml-security-c-1.7.3-2.1.mga6
Get the latest Linux and open source security news straight to your inbox.