USN-4784-1
Dashboard / Vulnerabilities / USN-4784-1
USN-4784-1
Summary: xerces-c vulnerabilities
Details: It was discovered that Xerces-C++ XML Parser mishandles certain kinds of external DTD references, resulting in a user-after-free. An attacker could use this vulnerability to cause a denial of service (crash) or possibly execute arbitrary code. This issue affected only Ubuntu 16.04 ESM. (CVE-2016-2099) It was discovered that Xerces-C++ XML Parser fails to successfully parse a DTD that is too deeply nested. An unauthenticated attacker could use this vulnerability to cause a denial of service. This issue affected only Ubuntu 16.04 ESM. (CVE-2016-4463) It was discovered that Xerces-C++ mishandles certain kinds of external DTD references, resulting in dereference of a NULL pointer. An attacker could use this vulnerability to cause a denial of service. (CVE-2017-12627)
References: https://ubuntu.com/security/notices/USN-4784-1, https://ubuntu.com/security/CVE-2016-2099, https://ubuntu.com/security/CVE-2016-4463, https://ubuntu.com/security/CVE-2017-12627
Affected packages
Package
Name: xerces-c
Purl: pkg:deb/ubuntu/xerces-c?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
