Candidate: CVE-2016-4463 PublicDate: 2016-07-08 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4463 http://xerces.apache.org/xerces-c/secadv/CVE-2016-4463.txt Description: Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD. Ubuntu-Description: It was discovered that Xerces-C XML Parser fails to successfully parse a DTD that is too deeply nested. An unauthenticated attacker could use this vulnerability to cause a denial of service. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=828990 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_xerces-c: upstream: http://svn.apache.org/viewvc?view=revision&revision=1747619 upstream_xerces-c: released (3.1.3+debian-2.1, 3.1.1-5.1+deb8u3, 3.1.1-3+deb7u4) precise_xerces-c: ignored (reached end-of-life) precise/esm_xerces-c: DNE (precise was needed) trusty_xerces-c: released (3.1.1-5.1+deb8u3build0.14.04.1) trusty/esm_xerces-c: released (3.1.1-5.1+deb8u3build0.14.04.1) vivid/stable-phone-overlay_xerces-c: DNE vivid/ubuntu-core_xerces-c: DNE wily_xerces-c: released (3.1.1-5.1+deb8u3build0.15.10.1) xenial_xerces-c: ignored (end of standard support, was needed) yakkety_xerces-c: ignored (reached end-of-life) zesty_xerces-c: ignored (reached end-of-life) artful_xerces-c: ignored (reached end-of-life) bionic_xerces-c: not-affected (3.2.0+debian-2) cosmic_xerces-c: not-affected (3.2.0+debian-2) disco_xerces-c: not-affected (3.2.0+debian-2) eoan_xerces-c: not-affected (3.2.0+debian-2) focal_xerces-c: not-affected (3.2.0+debian-2) groovy_xerces-c: not-affected (3.2.0+debian-2) hirsute_xerces-c: not-affected (3.2.0+debian-2) impish_xerces-c: not-affected (3.2.0+debian-2) jammy_xerces-c: not-affected (3.2.0+debian-2) devel_xerces-c: not-affected (3.2.0+debian-2)