Oval Definition:oval:org.cisecurity:def:14
Revision Date:2016-02-08Version:2
Title:DSA-3199-1 -- xerces-c -- security update
Description:Anton Rager and Jonathan Brossard from the Salesforce.com Product Security Team and Ben Laurie of Google discovered a denial of service vulnerability in xerces-c, a validating XML parser library for C++. The parser mishandles certain kinds of malformed input documents, resulting in a segmentation fault during a parse operation. An unauthenticated attacker could use this flaw to cause an application using the xerces-c library to crash.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2015-0252
DSA-3199-1
Platform(s):Debian GNU/kFreeBSD 7.0
Debian GNU/Linux 7.0
Product(s):xerces-c
Definition Synopsis
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND xerces-c is earlier than 0:3.1.1-3+deb7u1
  • BACK