UbuntuUpdates.org

Package "xmltooling"

Name: xmltooling

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • C++ XML parsing library with encryption support (development)
  • C++ XML parsing library with encryption support (API docs)
  • C++ XML parsing library with encryption support (runtime)
  • XML schemas for XMLTooling

Latest version: 1.5.3-2+deb8u3ubuntu0.1
Release: trusty (14.04)
Level: security
Repository: universe

Links



Other versions of "xmltooling" in Trusty

Repository Area Version
updates universe 1.5.3-2+deb8u3ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.5.3-2+deb8u3ubuntu0.1 2019-03-26 14:06:35 UTC

  xmltooling (1.5.3-2+deb8u3ubuntu0.1) trusty-security; urgency=high

  * SECURITY UPDATE: uncaught exception on malformed XML declaration
    Invalid data in the XML declaration causes an exception of a type that
    was not handled properly in the parser class and propagates an
    unexpected exception type.
    This generally manifests as a crash in the calling code, which in the
    Service Provider software's case is usually the shibd daemon process,
    but can be Apache in some cases. Note that the crash occurs prior to
    evaluation of a message's authenticity, so can be exploited by an
    untrusted attacker.
    - debian/patches/CVE-2019-9628.patch
    - CVE-2019-9628
    - https://shibboleth.net/community/advisories/secadv_20190311.txt
    - LP: #1819912

 -- Etienne Dysli Metref <email address hidden> Thu, 14 Mar 2019 11:56:34 +0100

Source diff to previous version
1819912 CVE-2019-9628 XML parser class fails to trap exceptions on malformed XML declaration
CVE-2019-9628 XML parser class fails to trap exceptions on malformed XML declaration

Version: 1.5.3-2+deb8u3build0.14.04.1 2018-03-21 00:06:30 UTC

  xmltooling (1.5.3-2+deb8u3build0.14.04.1) trusty-security; urgency=medium

  * fake sync from Debian (LP: #1752306)

Source diff to previous version
1752306 Security bug in XMLTooling-C before 1.6.4 [CVE-2018-0489]

Version: 1.5.3-2+deb8u2build0.14.04.1 2018-01-18 01:06:36 UTC

  xmltooling (1.5.3-2+deb8u2build0.14.04.1) trusty-security; urgency=medium

  * fake sync from Debian (LP: #1743762)

Source diff to previous version
1743762 Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

Version: 1.5.3-2+deb8u1build0.14.04.1 2015-08-07 21:06:48 UTC

  xmltooling (1.5.3-2+deb8u1build0.14.04.1) trusty-security; urgency=medium

  * fake sync from Debian




About   -   Send Feedback to @ubuntu_updates