|
|
| |
|
| |
xml-security-c: code execution
| Package(s): | xml-security-c |
CVE #(s): | CVE-2013-2210
|
| Created: | June 28, 2013 |
Updated: | July 3, 2013 |
| Description: |
From the Debian advisory:
Jon Erickson of iSIGHT Partners Labs discovered a heap overflow in
xml-security-c, an implementation of the XML Digital Security
specification. The fix to address CVE-2013-2154 introduced the
possibility of a heap overflow in the processing of malformed XPointer
expressions in the XML Signature Reference processing code, possibly
leading to arbitrary code execution. |
| Alerts: |
|
( Log in to post comments)
|
|
|