Debian Security Advisory
DLA-467-1 xerces-c -- LTS security update
- Date Reported:
- 12 May 2016
- Affected Packages:
- xerces-c
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 823863.
In Mitre's CVE dictionary: CVE-2016-2099. - More information:
-
XMLReader class can raise an exception if an invalid character is encountered, and the exception crosses stack frames in an unsafe way that causes a higher level exception handler to access an already-freed object.
For Debian 7
Wheezy
, these issues have been fixed in xerces-c version 3.1.1-3+deb7u3