Lucene search

K
debianDebianDEBIAN:DLA-181-1:20BFE
HistoryMar 27, 2015 - 9:14 p.m.

[SECURITY] [DLA 181-1] xerces-c security update

2015-03-2721:14:56
lists.debian.org
17

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

9.3

Confidence

High

EPSS

0.041

Percentile

92.3%

Package : xerces-c
Version : 3.1.1-1+deb6u1
CVE ID : CVE-2015-0252
Debian Bug : 780827

Anton Rager and Jonathan Brossard from the Salesforce.com Product
Security Team and Ben Laurie of Google discovered a denial of service
vulnerability in xerces-c, a validating XML parser library for C++. The
parser mishandles certain kinds of malformed input documents, resulting
in a segmentation fault during a parse operation. An unauthenticated
attacker could use this flaw to cause an application using the
xerces-c library to crash.

OSVersionArchitecturePackageVersionFilename
Debian7allxerces-c< 3.1.1-3+deb7u1xerces-c_3.1.1-3+deb7u1_all.deb
Debian6allxerces-c< 3.1.1-1+deb6u1xerces-c_3.1.1-1+deb6u1_all.deb

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

9.3

Confidence

High

EPSS

0.041

Percentile

92.3%