UbuntuUpdates.org

Package "xerces-c"

Name: xerces-c

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • validating XML parser library for C++ (development files)
  • validating XML parser library for C++ (documentation)
  • validating XML parser library for C++ (compiled samples)
  • validating XML parser library for C++

Latest version: 3.2.4+debian-1ubuntu0.23.10.1
Release: mantic (23.10)
Level: security
Repository: universe

Links



Other versions of "xerces-c" in Mantic

Repository Area Version
base universe 3.2.4+debian-1build1
updates universe 3.2.4+debian-1ubuntu0.23.10.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.2.4+debian-1ubuntu0.23.10.1 2024-01-16 13:08:00 UTC

  xerces-c (3.2.4+debian-1ubuntu0.23.10.1) mantic-security; urgency=medium

  * SECURITY UPDATE: use-after-free on external DTD scan
    - debian/patches/CVE-2018-1311-mitigation.patch: remove CVE-2018-1311 fix
      that also introduces memory leak.
    - debian/patches/series: update series file to remove
      CVE-2018-1311-mitigation.patch from the patch list.
    - debian/patches/CVE-2018-1311.patch: resolve issue XERCESC-2188.
    - CVE-2018-1311

 -- Camila Camargo de Matos <email address hidden> Mon, 08 Jan 2024 15:58:15 -0300

CVE-2018-1311 The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been



About   -   Send Feedback to @ubuntu_updates