FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

xercesi-c3 -- multiple vulnerabilities

Affected packages
xerces-c3 < 3.1.4

Details

VuXML ID cb09a7aa-5344-11e6-a7bd-14dae9d210b8
Discovery 2016-05-09
Entry 2016-07-26

Apache reports:

The Xerces-C XML parser fails to successfully parse a DTD that is deeply nested, and this causes a stack overflow, which makes a denial of service attack against many applications possible by an unauthenticated attacker.

Also, CVE-2016-2099: Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML document.

References

CVE Name CVE-2016-2099
CVE Name CVE-2016-4463
URL http://www.openwall.com/lists/oss-security/2016/05/09/7
URL https://xerces.apache.org/xerces-c/secadv/CVE-2016-4463.txt