LWN.net Logo

xml-security-c: code execution

Package(s):xml-security-c CVE #(s):CVE-2013-2210
Created:June 28, 2013 Updated:July 3, 2013
Description:

From the Debian advisory:

Jon Erickson of iSIGHT Partners Labs discovered a heap overflow in xml-security-c, an implementation of the XML Digital Security specification. The fix to address CVE-2013-2154 introduced the possibility of a heap overflow in the processing of malformed XPointer expressions in the XML Signature Reference processing code, possibly leading to arbitrary code execution.

Alerts:
Debian DSA-2717-1 2013-06-28
Mageia MGASA-2013-0193 2013-07-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds