Vulnerability Bulletins

DSA-3610 xerces-c - security update

   
Affected software Debian
 
Brandon Perry discovered that xerces-c, a validating XML parser libraryfor C++, fails to successfully parse a DTD that is deeply nested,causing a stack overflow. A remote unauthenticated attacker can takeadvantage of this flaw to cause a denial of service against applicationsusing the xerces-c library.

More info:

https://www.debian.org/security/2016/dsa-3610