New User, Welcome!     Login

Apache Xerces

[ MDVSA-2009:223 ] xerces-c

 Problem Description:

 A vulnerability has been found and corrected in xerces-c:
 
 Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in
 Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to
 cause a denial of service (application crash) via vectors involving
 nested parentheses and invalid byte values in simply nested DTD
 structures, as demonstrated by the Codenomicon XML fuzzing framework
 (CVE-2009-1885).
 

[ MDVSA-2009:223-1 ] xerces-c

 Problem Description:

 A vulnerability has been found and corrected in xerces-c:
 
 Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in
 Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to
 cause a denial of service (application crash) via vectors involving
 nested parentheses and invalid byte values in simply nested DTD
 structures, as demonstrated by the Codenomicon XML fuzzing framework
 (CVE-2009-1885).
 

Outdated and vulnerable OpenSource libraries used in "Deutsche Telekom" home banking software

- the library LIBCURL.DLL of the outdated, unsupported and
  vulnerable cURL 7.14.1 from 2005-09-05 (see
  <http://curl.haxx.se/libcurl/>);

- the libraries xerces-c_2_6.dll and xerces-depdom_2_6.dll of
  the outdated and unsupported Xerces 2.6 (see
  <http://xerces.apache.org/xerces-c/releases.html> as well as
  <http://xerces.apache.org/xerces-c/releases_archive.html>);

- the library CM32L7.DLL of vendor "combit GmbH" which has been



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!