Gentoo Archives: gentoo-announce

From: Robert Buchholz <rbu@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200903-19 ] Xerces-C++: Denial of Service
Date: Mon, 09 Mar 2009 16:14:31
Message-Id: 200903091501.26163.rbu@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200903-19
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Xerces-C++: Denial of Service
9 Date: March 09, 2009
10 Bugs: #240496
11 ID: 200903-19
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 An error in Xerces-C++ allows for a Denial of Service via malicious XML
19 schema files.
20
21 Background
22 ==========
23
24 Xerces-C++ is a validating XML parser written in a portable subset of
25 C++.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 dev-libs/xerces-c < 3.0.0-r1 >= 3.0.0-r1
34
35 Description
36 ===========
37
38 Frank Rast reported that the XML parser in Xerces-C++ does not
39 correctly handle an XML schema definition with a large maxOccurs value,
40 which triggers excessive memory consumption during the validation of an
41 XML file.
42
43 Impact
44 ======
45
46 A remote attacker could entice a user or automated system to validate
47 an XML file using a specially crafted XML schema file, leading to a
48 Denial of Service (stack consumption and crash).
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All Xerces-C++ users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=dev-libs/xerces-c-3.0.0-r1"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2008-4482
67 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4482
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 http://security.gentoo.org/glsa/glsa-200903-19.xml
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 http://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2009 Gentoo Foundation, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature