Security update for xerces-c
SUSE Patch
security@suse.de
SUSE Security Team
openSUSE-SU-2016:1744-1
Final
1
1
2016-07-05T14:21:37Z
current
2016-07-05T14:21:37Z
2016-07-05T14:21:37Z
cve-database/bin/generate-cvrf.pl
2017-02-24T01:00:00Z
Security update for xerces-c
xerces-c was updated to fix one security issue.
This security issue was fixed:
- CVE-2016-2099: Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++. It did not properly handle exceptions raised in the XMLReader class, which allowed context-dependent attackers to have unspecified impact via an invalid character in an XML document (bsc#979208).
The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)
http://lists.opensuse.org/opensuse-updates/2016-07/msg00016.html
E-Mail link for openSUSE-SU-2016:1744-1
https://www.suse.com/support/security/rating/
SUSE Security Ratings
openSUSE 13.2
libxerces-c-3_1-3.1.1-13.6.1
libxerces-c-3_1-32bit-3.1.1-13.6.1
libxerces-c-3_1-debuginfo-3.1.1-13.6.1
libxerces-c-3_1-debuginfo-32bit-3.1.1-13.6.1
libxerces-c-devel-3.1.1-13.6.1
xerces-c-3.1.1-13.6.1
xerces-c-debuginfo-3.1.1-13.6.1
xerces-c-debugsource-3.1.1-13.6.1
libxerces-c-3_1-3.1.1-13.6.1 as a component of openSUSE 13.2
libxerces-c-3_1-32bit-3.1.1-13.6.1 as a component of openSUSE 13.2
libxerces-c-3_1-debuginfo-3.1.1-13.6.1 as a component of openSUSE 13.2
libxerces-c-3_1-debuginfo-32bit-3.1.1-13.6.1 as a component of openSUSE 13.2
libxerces-c-devel-3.1.1-13.6.1 as a component of openSUSE 13.2
xerces-c-3.1.1-13.6.1 as a component of openSUSE 13.2
xerces-c-debuginfo-3.1.1-13.6.1 as a component of openSUSE 13.2
xerces-c-debugsource-3.1.1-13.6.1 as a component of openSUSE 13.2
Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML document.
CVE-2016-2099
openSUSE 13.2:libxerces-c-3_1-3.1.1-13.6.1
openSUSE 13.2:libxerces-c-3_1-32bit-3.1.1-13.6.1
openSUSE 13.2:libxerces-c-3_1-debuginfo-3.1.1-13.6.1
openSUSE 13.2:libxerces-c-3_1-debuginfo-32bit-3.1.1-13.6.1
openSUSE 13.2:libxerces-c-devel-3.1.1-13.6.1
openSUSE 13.2:xerces-c-3.1.1-13.6.1
openSUSE 13.2:xerces-c-debuginfo-3.1.1-13.6.1
openSUSE 13.2:xerces-c-debugsource-3.1.1-13.6.1
moderate
Please Install the update.
http://lists.opensuse.org/opensuse-updates/2016-07/msg00016.html
https://www.suse.com/security/cve/CVE-2016-2099.html
CVE-2016-2099
https://bugzilla.suse.com/979208
SUSE Bug 979208