Debian Security Advisory

DLA-467-1 xerces-c -- LTS security update

Date Reported:
12 May 2016
Affected Packages:
xerces-c
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 823863.
In Mitre's CVE dictionary: CVE-2016-2099.
More information:

XMLReader class can raise an exception if an invalid character is encountered, and the exception crosses stack frames in an unsafe way that causes a higher level exception handler to access an already-freed object.

For Debian 7 Wheezy, these issues have been fixed in xerces-c version 3.1.1-3+deb7u3