[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3199-1 xerces-c -- xerces-c

ID: oval:org.secpod.oval:def:602008Date: (C)2015-03-26   (M)2023-02-13
Class: PATCHFamily: unix




Anton Rager and Jonathan Brossard from the Salesforce.com Product Security Team and Ben Laurie of Google discovered a denial of service vulnerability in xerces-c, a validating XML parser library for C++. The parser mishandles certain kinds of malformed input documents, resulting in a segmentation fault during a parse operation. An unauthenticated attacker could use this flaw to cause an application using the xerces-c library to crash.

Platform:
Debian 7.0
Product:
libxerces-c-dev
Reference:
DSA-3199-1
CVE-2015-0252
CVE    1
CVE-2015-0252
CPE    2
cpe:/o:debian:debian_linux:7.x
cpe:/a:apache:libxerces-c-dev

© SecPod Technologies