FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2016-0729

This CVE name corresponds to:

Entered Topic
2016-02-28 xerces-c3 -- Parser Crashes on Malformed Input

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2016-0729
Phase Assigned(20151216)

Description

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.

References

Source Reference
BUGTRAQ 20160225 CVE-2016-0729: Apache Xerces-C XML Parser Crashes on Malformed Input
MISC http://packetstormsecurity.com/files/135949/Apache-Xerces-C-XML-Parser-Buffer-Overflow.html
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1727978
CONFIRM http://xerces.apache.org/xerces-c/secadv/CVE-2016-0729.txt
CONFIRM https://issues.apache.org/jira/browse/XERCESC-2061
DEBIAN DSA-3493
FEDORA FEDORA-2016-880b91c090
FEDORA FEDORA-2016-9ff972ca42
FEDORA FEDORA-2016-ae9ac16cf3