Lucene search

K
mageiaGentoo FoundationMGASA-2015-0136
HistoryApr 10, 2015 - 1:44 a.m.

Updated xerces-c packages fix security vulnerabilities

2015-04-1001:44:14
Gentoo Foundation
advisories.mageia.org
17

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.041

Percentile

92.3%

Updated xerces-c packages fix security vulnerability: Anton Rager and Jonathan Brossard from the Salesforce.com Product Security Team and Ben Laurie of Google discovered a denial of service vulnerability in xerces-c. The parser mishandles certain kinds of malformed input documents, resulting in a segmentation fault during a parse operation. An unauthenticated attacker could use this flaw to cause an application using the xerces-c library to crash (CVE-2015-0252).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchxerces-c< 3.1.2-1xerces-c-3.1.2-1.mga4

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.041

Percentile

92.3%