[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2717-1 xml-security-c -- heap overflow

ID: oval:org.secpod.oval:def:601065Date: (C)2013-06-28   (M)2023-02-20
Class: PATCHFamily: unix




Jon Erickson of iSIGHT Partners Labs discovered a heap overflow in xml-security-c, an implementation of the XML Digital Security specification. The fix to address CVE-2013-2154 introduced the possibility of a heap overflow in the processing of malformed XPointer expressions in the XML Signature Reference processing code, possibly leading to arbitrary code execution.

Platform:
Debian 7.0
Debian 6.0
Product:
libxml-security-c15
Reference:
DSA-2717-1
CVE-2013-2210
CVE-2013-2154
CVE    2
CVE-2013-2210
CVE-2013-2154
CPE    3
cpe:/o:debian:debian_linux:6.0
cpe:/a:apache:libxml-security-c15
cpe:/o:debian:debian_linux:7.0

© SecPod Technologies