UbuntuUpdates.org

Package "libxerces-c-doc"

Name: libxerces-c-doc

Description:

validating XML parser library for C++ (documentation)

Latest version: 3.2.4+debian-1ubuntu0.23.04.1
Release: lunar (23.04)
Level: updates
Repository: universe
Head package: xerces-c
Homepage: https://xerces.apache.org/xerces-c/

Links


Download "libxerces-c-doc"


Other versions of "libxerces-c-doc" in Lunar

Repository Area Version
base universe 3.2.4+debian-1build1
security universe 3.2.4+debian-1ubuntu0.23.04.1

Changelog

Version: 3.2.4+debian-1ubuntu0.23.04.1 2024-01-16 15:08:50 UTC

  xerces-c (3.2.4+debian-1ubuntu0.23.04.1) lunar-security; urgency=medium

  * SECURITY UPDATE: use-after-free on external DTD scan
    - debian/patches/CVE-2018-1311-mitigation.patch: remove CVE-2018-1311 fix
      that also introduces memory leak.
    - debian/patches/series: update series file to remove
      CVE-2018-1311-mitigation.patch from the patch list.
    - debian/patches/CVE-2018-1311.patch: resolve issue XERCESC-2188.
    - CVE-2018-1311

 -- Camila Camargo de Matos <email address hidden> Mon, 08 Jan 2024 15:56:22 -0300

CVE-2018-1311 The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been



About   -   Send Feedback to @ubuntu_updates