FS#44272 - [xerces-c] CVE-2015-0252: Apache Xerces-C XML Parser Crashes on Malformed Input
Attached to Project:
Arch Linux
Opened by Remi Gacogne (rgacogne) - Friday, 20 March 2015, 09:06 GMT
Last edited by Doug Newgard (Scimmia) - Friday, 20 March 2015, 16:04 GMT
Opened by Remi Gacogne (rgacogne) - Friday, 20 March 2015, 09:06 GMT
Last edited by Doug Newgard (Scimmia) - Friday, 20 March 2015, 16:04 GMT
|
Details
Hello,
A security issue has been found [1] in xerces-c < 3.1.2. I believe we should upgrade to 3.1.2. [1] https://xerces.apache.org/xerces-c/secadv/CVE-2015-0252.txt |
This task depends upon
Closed by Doug Newgard (Scimmia)
Friday, 20 March 2015, 16:04 GMT
Reason for closing: Fixed
Additional comments about closing: 3.1.2-1
Friday, 20 March 2015, 16:04 GMT
Reason for closing: Fixed
Additional comments about closing: 3.1.2-1
Comment by Doug Newgard (Scimmia) -
Friday, 20 March 2015, 15:20 GMT
Comment by
Levente Polyak (anthraxx) - Friday,
20 March 2015, 15:41 GMT
- Field changed: Status (Unconfirmed → Assigned)
- Task assigned to Florian Pritz (bluewind), Sven-Hendrik Haase (Svenstaro)
Orphan. Assigning to bluewind because freecad needs it, and
Svenstaro because megaglest needs it.
version 3.1.2 got synced to [extra] just in this moment, issue is
therefor fixed