Vulnerability Bulletins |
DSA-3199 xerces-c - security update |
|
| Affected software | Debian |
|
Anton Rager and Jonathan Brossard from the Salesforce.com ProductSecurity Team and Ben Laurie of Google discovered a denial of servicevulnerability in xerces-c, a validating XML parser library for C++. Theparser mishandles certain kinds of malformed input documents, resultingin a segmentation fault during a parse operation. An unauthenticatedattacker could use this flaw to cause an application using thexerces-c library to crash. More info: https://www.debian.org/security/2015/dsa-3199 |
|






