xerces-c 3.2.3+debian-3ubuntu0.1 source package in Ubuntu

Changelog

xerces-c (3.2.3+debian-3ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: use-after-free on external DTD scan
    - debian/patches/CVE-2018-1311-mitigation.patch: remove CVE-2018-1311 fix
      that also introduces memory leak.
    - debian/patches/series: update series file to remove
      CVE-2018-1311-mitigation.patch from the patch list.
    - debian/patches/CVE-2018-1311.patch: resolve issue XERCESC-2188.
    - CVE-2018-1311
  * SECURITY UPDATE: integer overflows in DFAContentModel class
    - debian/patches/CVE-2023-37536.patch: add limit checks to DFAContentModel
      class methods and resolve issue XERCESC-2241.
    - CVE-2023-37536

 -- Camila Camargo de Matos <email address hidden>  Wed, 17 Jan 2024 07:41:34 -0300

Upload details

Uploaded by:
Camila Camargo de Matos
Uploaded to:
Jammy
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Jammy updates universe libs
Jammy security universe libs

Downloads

File Size SHA-256 Checksum
xerces-c_3.2.3+debian.orig.tar.xz 1.5 MiB 25652e6ed8a55e9273d6514f7e2744678b6d51f5d88c03d4219fac0310393f8d
xerces-c_3.2.3+debian-3ubuntu0.1.debian.tar.xz 28.2 KiB 84eb304919f8850a2346bb8c715c82f2cc37b01ed8f092cf8210f09df0a08c3d
xerces-c_3.2.3+debian-3ubuntu0.1.dsc 2.1 KiB 886033b8f91d1284cb3923ba20a3ff1c8e2d9ef3aad9ba49ca69efe11dea08c6

View changes file

Binary packages built by this source

libxerces-c-dev: validating XML parser library for C++ (development files)

 Xerces-C++ is a validating XML parser written in a portable subset of
 C++. This package contains the development files for Xerces. It also
 contains sources to various sample files. The libxerces-c-samples
 package contains compiled versions of the samples.

libxerces-c-doc: validating XML parser library for C++ (documentation)

 Xerces-C++ is a validating XML parser written in a portable subset of
 C++. This package contains the developer documentation, including
 programming guides and API documentation.

libxerces-c-samples: validating XML parser library for C++ (compiled samples)

 Xerces-C++ is a validating XML parser written in a portable subset of
 C++. This package contains compiled versions of the samples. You
 probably don't want this package, but it can be useful if you are
 trying to reproduce a problem before reporting a bug that will be
 easy for the xerces developers to reproduce.

libxerces-c-samples-dbgsym: debug symbols for libxerces-c-samples
libxerces-c3.2: validating XML parser library for C++

 Xerces-C++ is a validating XML parser written in a portable subset of
 C++. Xerces-C++ makes it easy to give your application the ability
 to read and write XML data. A shared library is provided for parsing,
 generating, manipulating, and validating XML documents. Xerces-C++ is
 faithful to the XML 1.0 recommendation and associated standards (DOM
 1.0, DOM 2.0, SAX 1.0, SAX 2.0, Namespaces, XML Schema Part 1 and
 Part 2). It also provides experimental implementations of XML 1.1
 and DOM Level 3.0. The parser provides high performance, modularity,
 and scalability.

libxerces-c3.2-dbgsym: debug symbols for libxerces-c3.2